On Oct 24, 2013 5:37 AM, <[email protected]> wrote: > > Hi,ALL > > How can i do for the rule just analysis the specified log file. > i have a rule and just want analysis the "syslog",but now my ossec at the same time will analyze "secure > " > > how can i assign the log file for the rule? >
Try <hostname> in the rule. > > > -- > > --- > You received this message because you are subscribed to the Google Groups "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. > For more options, visit https://groups.google.com/groups/opt_out. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
