On Thu, Dec 1, 2011 at 2:13 PM, Peter M Abraham
<[email protected]> wrote:
> Hi Dan:
>
> It looks like the message for the /var/ossec/logs/alerts.log (and archives
> in compressed format) is in /var/ossec/etc/shared/system_audit_rcl.txt
>
> Do you know what I would have to change so that the agent name or agent id
> or agent host name was included on the same line of the outdated statement?
>
> FROM:
>
> System Audit: Web vulnerability - Outdated WordPress installation. File:
> **FULL PATH WAS HERE. Reference: http://sucuri.net/latest-versions .
>
> TO:
>
> * HOSTNAME*** System Audit: Web vulnerability - Outdated WordPress
> installation. File: ***FULL PATH WAS HERE. Reference:
> http://sucuri.net/latest-versions .
>
>
> ?
>
> Thank you.

My guess would be:
src/rootcheck/common_rcl.c

Reply via email to