Jeremy,
Its syslogd daemon tat this Open Source Uses.

Rgds
Tanishk

On Sat, Feb 5, 2011 at 12:48 AM, dan (ddp) <[email protected]> wrote:

> Hi Tanishk,
>
> Which syslog daemon are you using?
>
>
> On Fri, Feb 4, 2011 at 2:07 PM, tanishk lakhaani <[email protected]>
> wrote:
> > Hey thanks for replying !!!!
> >
> > Well I am trying the second option. Can u pls gimme some information on
> how
> > to set up log forwarding via syslog
> >
> > What I tried was (in /etc/syslog.conf):
> >
> > /var/log/messages <tab_space> local7.*
>
> I'm not sure what this is supposed to do. Are you trying to label
> everything in /var/log/messages as local7?
>
> > local7.* <tab_space> @ServerIP
> >
>
> This should send everything in local7 to ServerIP. If my above
> question is correct, you could just use the following instead:
> *.* <tab_space> @ServerIP
>
> I do this to send ALL syslog messages to my collector.
>
> > Am i doing the right way ?
> >
> > Regards
> > Tanishk
> >
>
>
>
>
> > On Sat, Feb 5, 2011 at 12:23 AM, Jeremy Lee <[email protected]> wrote:
> >>
> >> Do you have the OSSEC agent installed on the same box that ModSecurity
> is
> >> on? And is ModSec logging to the Apache logs? If so, make sure the OSSEC
> >> agent is monitoring the Apache logs and on your OSSEC server be sure to
> tune
> >> the ModSec rules (should be in the apache_rules.xml) to log/alert as
> >> required.
> >>
> >> Or, are you trying to forward the ModSec logs via syslog? If so you'll
> >> have to setup log forwarding via syslog/syslog-ng/rsyslog.
> >>
> >>
> >>
> >>
> >> On Fri, Feb 4, 2011 at 10:41 AM, tanishk lakhaani <
> [email protected]>
> >> wrote:
> >>>
> >>> Hi all,
> >>> I have deployed Mod-Security, bt I am unable to forward the logs of
> >>> Mod-Security to the OSSEC Server as well as a SIEM.
> >>>
> >>> Can anyone help me in fixing this.
> >>> Regards
> >>> Tanishk
> >
> >
> >
> > --
> > warm regards
> > Tanishk Lakhaani
> >
>



-- 
warm regards
Tanishk Lakhaani

Reply via email to