store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 9:08 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 
Author Message
 Post subject: Option to exclude mod_security alerts from OSSEC mails
Unread postPosted: Mon Apr 06, 2009 10:14 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Some of our servers are generating a lot of mod_security alerts. This is good, since it means it is doing its job. But the hourly OSSEC mails are getting kind of dominated by the endless lists of mod_security alerts and the really interesting events sometimes get overlooked because of this. I'd like to see an option to exclude mod_security alerts from OSSEC mails.

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Option to exclude mod_security alerts from OSSEC mails
Unread postPosted: Mon Apr 06, 2009 12:10 pm 
Offline
Forum Regular
Forum Regular

Joined: Tue Jul 15, 2008 2:38 pm
Posts: 704
Location: Sweden
Second that!


Top
 Profile  
 
 Post subject: Re: Option to exclude mod_security alerts from OSSEC mails
Unread postPosted: Mon Apr 06, 2009 5:49 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3242
Location: Chantilly, VA
Added to the feature queue. We may need to look into adding this into some sort of config tab too. I'll get with Scotts team to brainstorm some ideas.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: Option to exclude mod_security alerts from OSSEC mails
Unread postPosted: Tue Apr 07, 2009 7:37 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1843
You can easily modify the OSSEC rules to change the email trigger level, so that it only emails you for an alert over level 7 (or whatever level you want). However it gets overwritten when you run asl -u.

So count me in too!

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: Option to exclude mod_security alerts from OSSEC mails
Unread postPosted: Tue Apr 07, 2009 8:45 am 
Offline
Forum Regular
Forum Regular

Joined: Tue Jan 15, 2008 3:57 am
Posts: 478
Location: Netherlands
That would be very nice! Some of my OSSEC mail are 100Kb :(

_________________
best regards,

http://hosting.ber-art.nl
Professional Secure Linux Plesk Hosting


Top
 Profile  
 
 Post subject: Re: Option to exclude mod_security alerts from OSSEC mails
Unread postPosted: Sun Oct 11, 2009 4:53 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Mike, how is this request doing in the queue?

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
 Post subject: Re: Option to exclude mod_security alerts from OSSEC mails
Unread postPosted: Sun Oct 11, 2009 5:30 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
Nobody has had the time to look into it yet


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 7 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group