Hi.

In normal operation, OSSEC connects once, on startup, and closes the socket 
on exiting. But, for the behavior of UDP, there isn't an actual 
"connection", instead of this, every datagram is independent of the rest. 
Maybe this is the reason why the firewall considers every delivery as a 
connection.

But, if you are using the EventChannel log format at ossec.conf, I wonder 
if it's possible to discriminate the destination IP using the query.

Best regards.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to