Is anyone currently using OSSEC successfully with Snare? I have
analyzed these logs in the past, but not for awhile. I just tested Snare
agent v4.0 as well as another agent which outputs in the Snare format
(tab delimited) and the decoder doesn't match. I suspect it's something
on my side, but I don't see the problem yet.
