[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Rule 11 - excessive number of connections
Good Day, Everyone!
I'm running a low-profile-webserver, where the connections are pretty jumpy
(100 more or fewer connections matters more if that's all you'll get in a day
or if you get those every second), therefore I'm getting a lot of these
messages:
=============snipsnip============
Received From: /var/log/apache2/access.log
Rule: 11 fired (level 8) -> "Excessive number of connections during this
hour."
Portion of the log(s):
The average number of logs between 17:00 and 18:00 is 73. We reached 124.'
No Log Available (HOURLY_STATS)
=============snipsnip============
I'd like to tune that rule a bit, but I can't find a rule 11. Anyone knows
where that one is defined?
Have a nice weekend,
Lars
--~--~---------~--~----~------------~-------~--~----~
-~----------~----~----~----~------~----~------~--~---
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.