mod_security and prelude-lml
Colin <[email protected]> Thu, 6 Jan 2011 15:04:47 +0000
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
Hi everyone! I'm using mod_security and prelude-lml on a CentOS 5.4 server. I use prelude-lml to parse the logs from mod_security, throught apache error_log and sends it to another prewikka server. The problem is that an attack to the webserver which mod_security stops just generates a simple "HTTP Access denied" in prewikka with a classification_value_4=unknown. So I filter events with severity high or medium these alerts don't show up. How can I attribute an higher severity level to these attacks? Thanks, Colin _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-technologies.com/mailman/listinfo/prelude-user