I would look at what is generating the messages. Typical sources for
this are Windows logs being run through syslog, web attacks, and system
or network errors.
On 12/15/2010 10:58 AM, dan (ddp) wrote:
Comment out the warning in the source?
On Tue, Dec 14, 2010 at 4:18 PM, jplee3<[email protected]> wrote:
Ughh. Too many typos. My second paragraph I meant to say I *WANT* to
disable this so that the ossec.log doesn't grow...
TIA!
On Dec 14, 1:09 pm, jplee3<[email protected]> wrote:
Hi all,
I was wondering if there is a way to ignore the "ossec-logcollector:
Large message size:" warnings? I'm monitoring a log file where certain
lines are expected to be way too long. I've setup the decoder and
rules to specifically look for a certain condition (to which I know
the length of, and it will never generate a "Large message size"
warning.
Anyway, I don't want to disable this so that the ossec.log doesn't
grow wildly out of control and eat up space. I can foresee this
happening with the rate at which the log file being monitored grows.
Thanks!
Jeremy
--
R. Loyd Darby, OSSIM-OCSE
Project Manager DOC/NOAA/NMFS
Infrastructure coordinator
Southeast Fisheries Science Center
305-361-4297