On Tue, 5 Oct 2010 14:58:02 -0400, Christopher Moraes
<[email protected]> wrote:
> Hi,
> 
> We're using syslog-ng to centralize logs on a server.   The way the
system
> is setup is that *all* system logs (for unix, windows, apache, iis, etc)
> get
> written to a single file on the syslog server.
> 
> Can OSSEC be configured to analyse this type of combined syslog file?

That shouldn't be a problem. Just add the file to etc/ossec.conf, restart,
and prepare to start tuning!

-- 
[I] Immutable Security
Information Security, Privacy and Personal Liberty
http://www.immutablesecurity.com

Reply via email to