I have been unable to get ossec to ignore this particular error from this particular IP address even though I've added an ignore rule in local_rules.xml and restarted ossec
I've follow the manuals description of how to write an ignore rukle to no avail - so how would you guys go about it> thanks - jeff here's the error I want to ignore: Received From: (mysite-on-42) 75.36.241.42->/usr/local/website-logs/mysite_access_02042011.log Rule: 31151 fired (level 10) -> "Mutiple web server 400 error codes from same source ip." Portion of the log(s): blah, blah, blah....
