[ossec-list] Re: how to disregard all local log file messages with a certain hostname?

2008-11-03 Thread Eric Wemhoff
Thanks Peter and Daniel. Yeah I should probably reconfigure syslog eventually. For now I'm also trying to increase my understanding how rules get triggered. It looks like your suggestion works for me, to add an element in addition to . My first try was the following addition to local_rules.xml

[ossec-list] Re: how to disregard all local log file messages with a certain hostname?

2008-11-03 Thread Daniel Cid
Hi Eric, If you use the tag as Peter said, it will work properly (you can probably add 1 to make sure it is inspected for every event). However, OSSEC will still waste time processing this events, so it might be a better idea to configure your syslog server to log every remote syslog event from

[ossec-list] Re: how to disregard all local log file messages with a certain hostname?

2008-11-03 Thread Peter M. Abraham
Greetings Eric: You should be able to update local_rules.xml and use the " hostname" criteria. Thank you.