[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Rule ID explanation
Folks,
I am running the latest version of OSSEC HIDS and I installed the Web
UI for ease of use. On the main page of the WUI, under "Latest
Events", I am getting updates of what's going on on the machine being
watched. Beside each event is a "Rule ID: xxx", with the rule number
hyperlinked. The URL that the link takes me to is a wiki that is
supposed to be on that machine, which there isn't one. Where can I
find out details about each rule ID?
For example: "2007 Aug 09 11:16:59 Rule Id: 1002 level: 7"
the "1002" is hyperlinked but takes me to a non-existent wiki page on
the machine, http://xxx.xxx.xxx/wiki/rules/1002. I looked on the
OSSEC wiki site for something about "rule" but couldn't find
anything. Am I looking in the wrong place or what?
Thanks for the help.
FastZ
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.