It's a custom application - at this point, I could bother the devs about
changing the output of the logs but it probably won't happen to fast. I may
take up Dan's advice. Although, I'm assuming I'd have to recompile/run
install.sh again... something I'd want to avoid if possible.

On Wed, Dec 15, 2010 at 8:20 AM, loyd. darby <[email protected]> wrote:

> I would look at what is generating the messages.  Typical sources for this
> are Windows logs being run through syslog, web attacks, and system or
> network errors.
>
>
> On 12/15/2010 10:58 AM, dan (ddp) wrote:
>
>> Comment out the warning in the source?
>>
>> On Tue, Dec 14, 2010 at 4:18 PM, jplee3<[email protected]>  wrote:
>>
>>> Ughh. Too many typos. My second paragraph I meant to say I *WANT* to
>>> disable this so that the ossec.log doesn't grow...
>>>
>>> TIA!
>>>
>>> On Dec 14, 1:09 pm, jplee3<[email protected]>  wrote:
>>>
>>>> Hi all,
>>>>
>>>> I was wondering if there is a way to ignore the "ossec-logcollector:
>>>> Large message size:" warnings? I'm monitoring a log file where certain
>>>> lines are expected to be way too long. I've setup the decoder and
>>>> rules to specifically look for a certain condition (to which I know
>>>> the length of, and it will never generate a "Large message size"
>>>> warning.
>>>>
>>>> Anyway, I don't want to disable this so that the ossec.log doesn't
>>>> grow wildly out of control and eat up space. I can foresee this
>>>> happening with the rate at which the log file being monitored grows.
>>>>
>>>> Thanks!
>>>> Jeremy
>>>>
>>>
> --
> R. Loyd Darby, OSSIM-OCSE
> Project Manager DOC/NOAA/NMFS
> Infrastructure coordinator
> Southeast Fisheries Science Center
> 305-361-4297
>
>

Reply via email to