[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Re: My own rules
- To: ossec-list@xxxxxxxxxxxxxxxx
- Subject: [ossec-list] Re: My own rules
- From: "Daniel Cid" <daniel.cid@xxxxxxxxx>
- Date: Tue, 18 Sep 2007 22:18:43 -0300
- Authentication-results: mx.google.com; spf=pass (google.com: domain of daniel.cid@xxxxxxxxx designates 72.14.204.232 as permitted sender) smtp.mail=daniel.cid@xxxxxxxxx; dkim=pass (test mode) header.i=@xxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=WztDUV3hWrV0GbB9XvVDgItowcukzJVEQKglKf5u9jY=; b=sfURW27k40o+jMqNj7a9SWtgDxtdUo6Gw7yUjwbuQMA25KlTOWv3nqP+TQokFbgXJgWgJlcMGMLljyW4kxWjY4/0Il4QKekIhRrQRbL90Hh7t1lRMLlqRvu/zAvTfAqH26MorJCOvzHntOtWz1NpAAmb7TfaU2UIsrgzxsQFJ+4=
Hi Daniel,
Regarding how to write the rules, the following documents can help:
http://www.ossec.net/ossec-docs/auscert-2007-dcid.pdf
http://www.ossec.net/wiki/index.php/Know_How:Ignore_Rules
Thanks,
--
Daniel B. Cid
dcid ( at ) ossec.net
On 9/18/07, Peter M. Abraham <peter.m.abraham@xxxxxxxxx> wrote:
>
> Greetings Daniel:
>
> Custom rules can be placed in /var/ossec/rules/local_rules.xml
>
> Thank you.
>
>
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.