log_alert_levels versus syslog_output > level?

13 views
Skip to first unread message

Xtina Schelin

unread,
Sep 14, 2016, 4:26:57 PM9/14/16
to ossec-list
In the ossec.conf file, I see two settings:

alerts > log_alert_level
syslog_output > level

What is the meaningful difference between these two?

InfoSec

unread,
Sep 15, 2016, 2:29:03 AM9/15/16
to ossec-list
Alerts --> Alert level has to do with the event level threshold below which events are dropped and not placed in the alerts file.
Syslog --> Level has to do with the event level threshold below which events are not forwarded via csyslogd to syslog receiver.
Reply all
Reply to author
Forward
0 new messages