Letting everyone know, my 'OSSEC newness' has bitten my in the arse..again. 
 
Everything works great with the issue here.  I was updating my test log 
prior to starting up OSSEC.
Essentially, during my testing, I had the timing down wrong.
Sorry for the confusion.

On Tuesday, July 14, 2015 at 9:41:19 PM UTC-5, Mark Feferman wrote:
>
> Under what circumstances would the ossec-logtest succeed (indicated with 
> **Alert to be generated.
>  after Phase 3), but an actual alert is never sent when a log file is 
> 'analyzed' on an agent box that contains an offending (triggering) entry?
>
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to