If the log messages are making it into a log file monitored by OSSEC, it will alert on it.
On Mon, Nov 1, 2010 at 10:18 AM, Michael Larsen <[email protected]> wrote: > My OSSEC server is also my syslog server. I recently enabled remote logging > to it on several systems, but didn't install/register the OSSEC agent on > those systems. I've been getting sshd login notifications via OSSEC since > enabling syslog on them. Is it normal behavior for the OSSEC server to alert > on authentication activity for unregistered systems? Thanks in advance. > > Mike > >
