On 10/28/2013 02:20 PM, Gabriel Holder wrote:
I created a new decoder/rule to monitor an agent's logfile.
It's sending me alerts which is great but it seems to be sending alerts
from OLD entries.
How can I adjust this so that ossec will only send new entries but
ignore the old ones?
OSSEC should never do this. Are you sure these are not in the log file
that OSSEC is monitoring?
--
---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.