On Thu, Oct 28, 2010 at 7:26 PM, Hac Phan <[email protected]> wrote: > Hi, > > I want to have OSSEC on my syslog server. However, when it monitors that > server's log files (e.g. /var/log/messages), OSSEC inadvertently captures the > errors from other servers. This reesults in a duplicate alert because OSSEC > caught the issue on the original server and now once again on the syslog > server. > > How should I retify this problem? >
Install it on a different system. > On an unrelated note: I know OSSEC runs as an unprivilege user (ossec), the > how > does it have read access to the log files that I specify in ossec.conf when I > don't allow world readable log files (as I should). > > Thanks in advance. > I think the process that collects logs runs as root. > -- > Hac Phan > Unix System Administrator > Network & Infrastructure, RSSP-IT > UC Berkeley >
