It appears that OSSEC does not support log files encoded with UTF-8/16? I haven't seen any specific documentation on it, so I wanted to confirm. From the screenshot below, you can see that the once a null char is encountered (after the T), it fails to read any further.
http://screencast.com/t/tqozmdlzje -Josh -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
