On Tue, 5 Oct 2010 14:58:02 -0400, Christopher Moraes <[email protected]> wrote: > Hi, > > We're using syslog-ng to centralize logs on a server. The way the system > is setup is that *all* system logs (for unix, windows, apache, iis, etc) > get > written to a single file on the syslog server. > > Can OSSEC be configured to analyse this type of combined syslog file?
That shouldn't be a problem. Just add the file to etc/ossec.conf, restart, and prepare to start tuning! -- [I] Immutable Security Information Security, Privacy and Personal Liberty http://www.immutablesecurity.com
