This message can be safely ignored.
This is a legacy feature in Atomic OSSEC and Atomic Protector and is no longer used. Atomic OSSEC and Atomic Protector have an advanced antimalware system and this feature has been deprecated.
Users may however choose to use this file to contain custom user generated signatures for the legacy rootkit detection system. The legacy scanner is a string scanner, it looks for strings in a given file and if there is a match an alert is generated. The format of the file is:
# file_name !string_to_search!Description
Regular expressions are available depending on native support in the OS it was built for. For example:
identd !bash|^/bin/sh|file\.h|proc\.h|/dev/[^n]|^/bin/.*sh!