[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] Chatty PIX rules




Have we come up with a workable way to suppress or threshold down alerts for certain devices? I have several PIXes sending syslogs to the OSSEC box and I'm being flooded with alerts. There were 139 of them last night for one PIX as it was doing what it's supposed to and dropping traffic based on ACLs. Maybe I need to turn something down on the PIX? I do have it configured with "logging trap debugging".


OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.