<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Week of OSSEC Day 7: Developing a Workflow</title>
	<atom:link href="http://www.immutablesecurity.com/index.php/2009/10/31/week-of-ossec-day-7-developing-a-workflow/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.immutablesecurity.com/index.php/2009/10/31/week-of-ossec-day-7-developing-a-workflow/</link>
	<description>Information Security, Privacy and Personal Liberty</description>
	<lastBuildDate>Sun, 29 Jan 2012 17:21:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Michael Starks</title>
		<link>http://www.immutablesecurity.com/index.php/2009/10/31/week-of-ossec-day-7-developing-a-workflow/comment-page-1/#comment-913</link>
		<dc:creator>Michael Starks</dc:creator>
		<pubDate>Fri, 09 Sep 2011 01:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.immutablesecurity.com/?p=269#comment-913</guid>
		<description>Hello Harika, 

Sorry if there was a misunderstanding, but what I meant by the post was that you can use some sort of GUI to view the events that you would not normally get alerted on. OSSEC can also be configured to run daily reports, and you could cron this to match the workflow I mentioned in the post, but the better solution is to use a good GUI front-end for that.

Thanks,
Mike</description>
		<content:encoded><![CDATA[<p>Hello Harika, </p>
<p>Sorry if there was a misunderstanding, but what I meant by the post was that you can use some sort of GUI to view the events that you would not normally get alerted on. OSSEC can also be configured to run daily reports, and you could cron this to match the workflow I mentioned in the post, but the better solution is to use a good GUI front-end for that.</p>
<p>Thanks,<br />
Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harika Tandra</title>
		<link>http://www.immutablesecurity.com/index.php/2009/10/31/week-of-ossec-day-7-developing-a-workflow/comment-page-1/#comment-910</link>
		<dc:creator>Harika Tandra</dc:creator>
		<pubDate>Thu, 08 Sep 2011 15:28:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.immutablesecurity.com/?p=269#comment-910</guid>
		<description>Hi Michael,

I have started deploying OSSEC for my group last week. Your blog posts were very helpful. Thank you !! 
I am able to write new rules to tune ossec and reduce noise but I am not able to figure out how you group alerts by level to be sent once a day/week/month as you suggest in this blog post. I would appreciate any pointers you can provide regarding this. 

Thanks again.

Regards,
Harika Tandra.</description>
		<content:encoded><![CDATA[<p>Hi Michael,</p>
<p>I have started deploying OSSEC for my group last week. Your blog posts were very helpful. Thank you !!<br />
I am able to write new rules to tune ossec and reduce noise but I am not able to figure out how you group alerts by level to be sent once a day/week/month as you suggest in this blog post. I would appreciate any pointers you can provide regarding this. </p>
<p>Thanks again.</p>
<p>Regards,<br />
Harika Tandra.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

