Skip to content

fire OSSEC rules by using a command #9200

Discussion options

You must be logged in to vote

The situation is a bit weird but lets say that I would like to try this for a school project so I can compare how many event loggings I have reduced by editing or disabling rules. So I would like to trigger a rule then edit/ disable it and then trigger it again to show that my rule worked.

If this is for a school project, we can't do your homework for you but you might consider using something like logger to generate your own logs that match rules.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@LucasCortooms
Comment options

Answer selected by LucasCortooms
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants