Hi Shane, On Wed, Jan 26, 2011 at 10:45 AM, Castle, Shane <[email protected]> wrote: > Here's the message, copied from the web-ui: > > 2011 Jan 26 05:57:42 Rule Id: 11 level: 4 > Location: (waf02) 172.31.251.2->/var/log/messages > Excessive number of events (above normal). > The average number of logs between 5:00 and 6:00 is 1935. We reached > 2517. > > When I went to look, there were only 242: > > # fgrep 'Jan 26 05:' /var/log/messages | wc -l > 242 > > Why the difference? I'll look at the source a bit later but I was > wondering if this was a known issue. > > -- > Shane Castle > Data Security Mgr, Boulder County IT > CISSP GSEC GCIH > >
Are you only monitoring /var/log/messages? No other logfiles? Is this an agent, local, or server? You can find all of the alerts in /var/ossec/logs/alerts/alerts.log.
