From OSSEC Wiki
- OSSEC & BASE
- Monolithic rules file
- HOW-TO Add/enable Nmap Correlation
- Know how to ignore rules that generate too many false positives
- SuSE10.1 and ossec
- PIX and IOS Syslog Config examples
- Troubleshooting High CPU utilization by Windows OSSEC HIDS agent
- Detecting port scanner with OSSEC HIDS and iplog
- FreeBSD optimization
- Integration & Deployment with cfengine