Is it still true that for IIS logfile format the logs have to be set to daily?
I know with daily logs you can do u_ex%y%m%d.log so it seems you should be able to do u_ex%y%m%d%H.log and get IIS logs that are rotated hourly. I am trying to pull some IIS logs from Windows Azure servers, in Windows Azure IIS logs are rotated hourly and written to a cloud storage area. I have worked out pulling the logs down to a local server but I wasn't sure if OSSEC would accept IIS logs in with an hourly filename? Also if I pulled overwrote the hourly IIS log multiple times in the hour I wasn't sure how OSSEC would react to that event either? Thanks. James Whittington -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/groups/opt_out.