On Tue, Oct 25, 2011 at 11:42 AM, James M Pulver <[email protected]> wrote: > The big issue I’ve had is that if I use the built in syslog generation, all > the events appear to come from the OSSEC server. So if it can fake the > “location” to be where it actually comes from, then I could indeed use any > syslog frontend.
I believe you can do this with rsyslog and syslog-ng.
