Webmin Break-in Attempts and OSSEC/HIDS
I use OSSEC/HIDS for active security on my server and would like to have any webmin break-in attempt report to OSSEC to automatically add to hosts.deny and/or my firewall to block/shun the offending IP address.
However, in order for OSSEC to see this happening it needs to look at the syslogs and the format must follow Syslog RFC. The only log that I can tell that documents an unauthorized access is miniserv.error which does not follow the Syslog RFC format. Is there anyway to to change this to comply with the proper format? How about adding a webmin break-in to secure.log?