[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Re: What is the best way to preserve the excluded rules in ossec.conf
- To: ossec-list@xxxxxxxxxxxxxxxx
- Subject: [ossec-list] Re: What is the best way to preserve the excluded rules in ossec.conf
- From: "Daniel Cid" <daniel.cid@xxxxxxxxx>
- Date: Mon, 13 Aug 2007 23:20:52 -0300
- Dkim-signature: a=rsa-sha1; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=f9w/PDWSbUY9BPAnuPnxuTvTdkYW9uXFtEDmi+LBsJCaFyOE4WHF5sbRBS4VMNw1UsKW+AkHfAq5XrhcPaxYwtbwtwv9LGVt8VQnmGTrc+tfHlaL3ulDdiv4ryZRhZE8WJXx6Pfygampu/0tZCKnOXwe6hLo6CAq225DFe7fJbE=
Hi Peter,
I see now what you mean. Our upgrade process currently does not handle that
very well and we should fix it for the next version. If you don't mind
opening a bug
about it, I will make sure to look at it before the next release.
http://www.ossec.net/bugs/
Thanks,
--
Daniel B. Cid
dcid ( at ) ossec.net
On 8/12/07, Peter M. Abraham <peter.m.abraham@xxxxxxxxx> wrote:
>
> Greetings Daniel:
>
> I don't mean on an individual rule basis, but in ossec.conf there are
> includes for rules which are not applicable for our environment.
>
> Such as
>
> <include>symantec-av_rules.xml</include>
>
> Right now I comment such rules out; but when I upgraded from 1.2 to
> 1.3, the upgrade process put them all back.
>
> Is there a way I can avoid that happening to our ossec server?
>
> Thank you.
>
>
>
>
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.