Hi All, I have rule 5712 configured on Ossec agents which blocks the Src Ipaddress .
Is there any option to to receive Email Alert if a Specific Source ip is blocked by firewall-drop.sh rule . I tried by writing a decoder but was unsuccessful. Thanks Regards John -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
