Did you restart the ossec processes on the manager? On Apr 4, 2012 9:48 AM, "nick talbot" <[email protected]> wrote:
> I have the following entry in my local_rules.xml, however i am still > receiving email alerts on this rule. Should I also set it to 0 in the > msauth_rules.xml? > > <rule id="100030" level="0"> > <if_sid>18153</if_sid> > <description>List of rules to be ignored.</description> > </rule> >
