[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] Re: How to replace hostname with IP in alerts?



Hi DM,

Ossec uses whatever the log message provided to it. If it come as a
hostname, it will use that, since it does no hostname lookup based on
logs. Btw, most applications have configuration parameters to log the
IP address instead of the hostname...

Example on how to disable hostname lookup on sshd:

http://www.ossec.net/wiki/index.php/Sshd

Hope it helps.

--
Daniel B. Cid
dcid ( at ) ossec.net

On 5/26/07, deltamails@xxxxxxxxx <deltamails@xxxxxxxxx> wrote:
>
>
> When I get alerts I want to get the IP address inplace of hostname. How to
> configure the ossec.conf for the same.
>
>
> Regards,
> DM


OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.