[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] What is the best way to modify included rules for alert levels



Greetings:

What is the best way to modify the included ossec rules to change the
alert levels so those changes will be preserved come upgrade time?

If I copy the rule set to local_rules.xml, then do rules in
local_rules.xml that have the exact same rule id as another file (say
apache_rules.xml) override apache_rules.xml for the given rule in
question?

Thank you.



OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.