HIDS 593
From Atomicorp Wiki
Rule 1 | |
---|---|
Status | Active |
Alert Message | Ossec event log |
Contents |
Description
This indicates that the OSSEC event log has been cleared. This is an internal tracking rule that identifies when the ossec.log file has been cleared, typically during manual maintenance.
What you should do
None
Troubleshooting
False Positives
There are no false positives with this rule.
Tuning Guidance
There is no guidance for tuning this rule.
Additional Information
Support
If you are unsure about how to respond to this alert, please contact Atomicorp support. We're here to help you!
Similar Rules
None.
Knowledge Base Articles
None.
Outside References
None.