Hey thanks for replying !!!!

Well I am trying the second option. Can u pls gimme some information on how
to set up log forwarding via syslog

What I tried was (in /etc/syslog.conf):

/var/log/messages <tab_space> local7.*
local7.* <tab_space> @ServerIP

Am i doing the right way ?

Regards
Tanishk

On Sat, Feb 5, 2011 at 12:23 AM, Jeremy Lee <[email protected]> wrote:

> Do you have the OSSEC agent installed on the same box that ModSecurity is
> on? And is ModSec logging to the Apache logs? If so, make sure the OSSEC
> agent is monitoring the Apache logs and on your OSSEC server be sure to tune
> the ModSec rules (should be in the apache_rules.xml) to log/alert as
> required.
>
> Or, are you trying to forward the ModSec logs via syslog? If so you'll have
> to setup log forwarding via syslog/syslog-ng/rsyslog.
>
>
>
>
>
> On Fri, Feb 4, 2011 at 10:41 AM, tanishk lakhaani 
> <[email protected]>wrote:
>
>> Hi all,
>> I have deployed Mod-Security, bt I am unable to forward the logs of
>> Mod-Security to the OSSEC Server as well as a SIEM.
>>
>> Can anyone help me in fixing this.
>> Regards
>> Tanishk
>>
>
>


-- 
warm regards
Tanishk Lakhaani

Reply via email to