Hi,

I want to have OSSEC on my syslog server. However, when it monitors that
server's log files (e.g. /var/log/messages), OSSEC inadvertently captures the
errors from other servers. This reesults in a duplicate alert because OSSEC
caught the issue on the original server and now once again on the syslog server.

How should I retify this problem?

On an unrelated note: I know OSSEC runs as an unprivilege user (ossec), the how
does it have read access to the log files that I specify in ossec.conf when I
don't allow world readable log files (as I should).

Thanks in advance.

-- 
Hac Phan
Unix System Administrator
Network & Infrastructure, RSSP-IT
UC Berkeley

Attachment: pgpc27367SPmU.pgp
Description: PGP signature

Reply via email to