If the log messages are making it into a log file monitored by OSSEC,
it will alert on it.

On Mon, Nov 1, 2010 at 10:18 AM, Michael Larsen <[email protected]> wrote:
> My OSSEC server is also my syslog server. I recently enabled remote logging
> to it on several systems, but didn't install/register the OSSEC agent on
> those systems. I've been getting sshd login notifications via OSSEC since
> enabling syslog on them. Is it normal behavior for the OSSEC server to alert
> on authentication activity for unregistered systems? Thanks in advance.
>
> Mike
>
>

Reply via email to