See here:

http://groups.google.com/group/ossec-list/browse_thread/thread/cd0ac9bbe823834b?pli=1

http://www.ossec.net/dcid/?p=139



On Mon, Jan 24, 2011 at 1:35 PM, ash kumar <[email protected]> wrote:

> I would like to forward some of the logs (MS Event Logs) to another
> Log management appliance.
>
> This problem breaks down into two parts.
> 1. Selectively forward syslogs --> This is easily configured in
> ossec.conf
> 2. Strip ossec specific parts of the log and forward the rest to the
> log management appliance which can parse native Event Logs.
>
> It is the second part that I have not been able to figure out. I
> suspect this would involve a perl script stripping and forwarding the
> logs.
> has anyone tried this?
>
> Thanks
>
> Ash

Reply via email to