Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Change the default AR level to 7. #991

Merged
merged 1 commit into from
Nov 23, 2016
Merged

Conversation

ddpbsd
Copy link
Member

@ddpbsd ddpbsd commented Nov 21, 2016

The default email level is 7, and I'm not entirely convinced it's ok to block something automatically
with no notice whatsoever.
Brought up by Christina Plummer on the user list.

I'm not entirely convinced it's ok to block something automatically
with no notice whatsoever.
Brought up by Christina Plummer on the user list.
@atomicturtle
Copy link
Member

I dont have a problem with bumping this, but I think the reasoning here was that it was an example of having a bucket for high-volume AR's that you want to block and ignore as a 6 and a more important block that you want a notification on at 7

@ddpbsd
Copy link
Member Author

ddpbsd commented Nov 23, 2016

That makes sense, buuuuuut I don't like blocking anything by default that isn't alerted on.
Either way, the documentation on this stuff needs to improve. I don't think anyone should expect AR to be flawless out of the box, but making it less surprising is a reasonable start.

@atomicturtle atomicturtle merged commit d944491 into ossec:master Nov 23, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants