[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] Rule ID explanation



Folks,
I am running the latest version of OSSEC HIDS and I installed the Web
UI for ease of use.  On the main page of the WUI, under "Latest
Events", I am getting updates of what's going on on the machine being
watched.  Beside each event is a "Rule ID: xxx", with the rule number
hyperlinked.  The URL that the link takes me to is a wiki that is
supposed to be on that machine, which there isn't one.  Where can I
find out details about each rule ID?

For example:  "2007 Aug 09 11:16:59 Rule Id: 1002 level: 7"

the "1002" is hyperlinked but takes me to a non-existent wiki page on
the machine, http://xxx.xxx.xxx/wiki/rules/1002.  I looked on the
OSSEC wiki site for something about "rule" but couldn't find
anything.  Am I looking in the wrong place or what?

Thanks for the help.
FastZ



OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.