OSSEC 101: Alert Output:

OSSEC has a number of output options for alerts.

Logfile:

Email:

  • GeoIP

Syslog:

Database:

  • MySQL
  • PostgreSQL

Prelude:

CEF: