You can add custom rules to /var/ossec/rules/local_rules.xml. You can
use these rules to either look for something that isn't covered by the
default rules or to ignore something you don't want to see.

On Mon, Apr 30, 2012 at 1:59 PM, A-Dubbs <[email protected]> wrote:
> Just learning OSSEC here using the documentation on ossec.net to
> troubleshoot some problems.I am receiving excessive HIDS notifications
> in a log for  a windows machines(an agent) in my OSSEC environment.
> When looking at the security log, it seems that too many events are
> being added to the queue, mostly system activity, in the security log
> of the windows machine. Which files should I look to, to start
> adjusting configurations for what I want to ignore and what I would
> like to include in the alerts.log file? I looked at ossec.conf and now
> I just don't see a file where I can modify alerts going into the
> alerts.log file. Thank you.

Reply via email to