Skip to content
Discussion options

You must be logged in to vote

Thanks @dougburks but because this removes the function in totality, that is a bit overkill because my goal is to keep at least some of the rules albeit with modifications. However, I have found that the rules reside in /var/ossec/etc/shared/ with the key rule file being system_audit_ssh.txt.

However, there is another issue where the <frequency> setting in ossec.conf is not being respected; probably open a new discussion on that if need be.

Thanks.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by cyb3rz3us
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants