Skip to content
Discussion options

You must be logged in to vote

In that case, try this:

  • Copy the ossec.conf file from /opt/so/saltstack/default/salt/wazuh/files/server/ossec.conf to /opt/so/saltstack/local/salt/wazuh/files/server/ossec.conf

  • Add rule_exclude directives (as in line 212) for any of those rule files from /opt/so/rules/hids/ruleset/rules that you don't want the server to alert on.

  • Restart the Wazuh server with so-wazuh-restart.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@eSupportSquirrel
Comment options

@InfosecGoon
Comment options

Answer selected by eSupportSquirrel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants