Re: RE: Re: OSSEC and Windows messages May 17 2010 12:27PM
evilwon12 yahoo com
Actually got this working. I am still not 100% sure why it was not working earlier.

What I had to do was include the full path, out to the directory I want to exclude, in my match.

As I said, it was C:\Windows/system32/dir1/dir2/dir3/.../dirx/file.out

I was trying to match only on "dirM" and that was constantly failing. By putting the entire path into my match rule, it worked.

Some people mentioned that I could do this at the system level, but that is a huge pain when you have 40+ clients. I would rather do this once at the server level and be done with it.

Thanks everyone!

