On Thu, Dec 1, 2011 at 2:13 PM, Peter M Abraham <[email protected]> wrote: > Hi Dan: > > It looks like the message for the /var/ossec/logs/alerts.log (and archives > in compressed format) is in /var/ossec/etc/shared/system_audit_rcl.txt > > Do you know what I would have to change so that the agent name or agent id > or agent host name was included on the same line of the outdated statement? > > FROM: > > System Audit: Web vulnerability - Outdated WordPress installation. File: > **FULL PATH WAS HERE. Reference: http://sucuri.net/latest-versions . > > TO: > > * HOSTNAME*** System Audit: Web vulnerability - Outdated WordPress > installation. File: ***FULL PATH WAS HERE. Reference: > http://sucuri.net/latest-versions . > > > ? > > Thank you.
My guess would be: src/rootcheck/common_rcl.c
