Did you restart the ossec processes on the manager?
On Apr 4, 2012 9:48 AM, "nick talbot" <[email protected]> wrote:

> I have the following entry in my local_rules.xml, however i am still
> receiving email alerts on this rule.  Should I also set it to 0 in the
> msauth_rules.xml?
>
>  <rule id="100030" level="0">
>    <if_sid>18153</if_sid>
>    <description>List of rules to be ignored.</description>
>  </rule>
>

Reply via email to