We need to consolidate our OSSEC-HIDS logs to have one common facility and centralized logging. I would like to ask if someone might have started integrating OSSEC-HIDS to LEM?
Hi,
LEM includes an OSSEC response log connector which captures any actions taken by OSSEC, however we do not currently have an OSSEC-HIDS connector. Assuming your LEM is under maintenance, it is best to raise a support ticket to submit a connector request - they will require a log sample & information such as log file location, names, rotation, etc.
Hi jhynds, thanks for the info, we will ask support team if they can help us.