Hi Dan: It looks like the message for the /var/ossec/logs/alerts.log (and archives in compressed format) is in /var/ossec/etc/shared/system_audit_rcl.txt
Do you know what I would have to change so that the agent name or agent id or agent host name was included on the same line of the outdated statement? FROM: System Audit: Web vulnerability - Outdated WordPress installation. File: **FULL PATH WAS HERE. Reference: http://sucuri.net/latest-versions<http://www.linkedin.com/redirect?url=http%3A%2F%2Fsucuri%2Enet%2Flatest-versions&urlhash=ljts&_t=tracking_disc>. TO: * HOSTNAME*** System Audit: Web vulnerability - Outdated WordPress installation. File: ***FULL PATH WAS HERE. Reference: http://sucuri.net/latest-versions<http://www.linkedin.com/redirect?url=http%3A%2F%2Fsucuri%2Enet%2Flatest-versions&urlhash=ljts&_t=tracking_disc>. ? Thank you.
