I have been unable to get ossec to ignore this particular error from this
particular IP address even though I've added an ignore rule in
local_rules.xml and restarted ossec

I've follow the manuals description of how to write an ignore rukle to no
avail - so how would you guys go about it>

thanks - jeff

here's the error I want to ignore:

Received From: (mysite-on-42)
75.36.241.42->/usr/local/website-logs/mysite_access_02042011.log
Rule: 31151 fired (level 10) -> "Mutiple web server 400 error codes from
same source ip."
Portion of the log(s):

blah, blah, blah....

Reply via email to