[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] Re: Can't get OSSEC to fire active response for custom proftpd rule



Michael Starks wrote:
> Try 21 or 22 invalid logins in 60 seconds.
>
> -Mike
>   
Hi Mike,

Thanks for the suggestion! I try over 25 invalid logins and still ossec 
active response doesn't fire. Not really sure why but I think it might 
be related to my rule or the underlaying proftpd group rule 11200.

SW


OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.