Hi, I want to have OSSEC on my syslog server. However, when it monitors that server's log files (e.g. /var/log/messages), OSSEC inadvertently captures the errors from other servers. This reesults in a duplicate alert because OSSEC caught the issue on the original server and now once again on the syslog server.
How should I retify this problem? On an unrelated note: I know OSSEC runs as an unprivilege user (ossec), the how does it have read access to the log files that I specify in ossec.conf when I don't allow world readable log files (as I should). Thanks in advance. -- Hac Phan Unix System Administrator Network & Infrastructure, RSSP-IT UC Berkeley
pgpc27367SPmU.pgp
Description: PGP signature
