Periodically (2 or 3 times a day) OSSEC is somehow combining logs it receives from two separate hosts and reports them as if they were from just one host. Has anyone else seen this and if so, is there a fix?
I'm happy to supply example messages received. I just didn't want to post specifics with hostnames etc. Thanks in advance! Ralphy
