Hi Shane,

On Wed, Jan 26, 2011 at 10:45 AM, Castle, Shane
<[email protected]> wrote:
> Here's the message, copied from the web-ui:
>
> 2011 Jan 26 05:57:42 Rule Id: 11 level: 4
> Location: (waf02) 172.31.251.2->/var/log/messages
> Excessive number of events (above normal).
> The average number of logs between 5:00 and 6:00 is 1935. We reached
> 2517.
>
> When I went to look, there were only 242:
>
> # fgrep 'Jan 26 05:' /var/log/messages | wc -l
> 242
>
> Why the difference? I'll look at the source a bit later but I was
> wondering if this was a known issue.
>
> --
> Shane Castle
> Data Security Mgr, Boulder County IT
> CISSP GSEC GCIH
>
>

Are you only monitoring /var/log/messages? No other logfiles?
Is this an agent, local, or server?
You can find all of the alerts in /var/ossec/logs/alerts/alerts.log.

Reply via email to