mod_security and prelude-lml

Colin <[email protected]> Thu, 6 Jan 2011 15:04:47 +0000
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
Hi everyone!
I'm using mod_security and prelude-lml on a CentOS 5.4 server.
I use prelude-lml to parse the logs from mod_security, throught apache
error_log and sends it to another prewikka server.

The problem is that an attack to the webserver which mod_security
stops just generates a simple "HTTP Access denied" in prewikka with a
classification_value_4=unknown.
So I filter events with severity high or medium these alerts don't show up.

How can I attribute an higher severity level to these attacks?

Thanks,
Colin
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-technologies.com/mailman/listinfo/prelude-user