Running the ossec server in a docker container, makes sense, and I run the Wazuh fork of ossec in their provided container with logstash / kibana4.
Running ossec agent in a container makes no sense to me. I would suggest instead that you use the docker logging driver to reroute stdout from your containers to syslog, and run ossec agent on your docker host, if you want to monitor your containers. Regardless, running the agent within a container will make it highly problematic to monitor the underlying host. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.