Re: [ossec-list] Re: OSSEC + CIS benchmark tests

2015-05-15 Thread dan (ddp)
On Tue, May 12, 2015 at 6:57 PM, autodidactic theoriginalg...@gmail.com wrote: Are there any updates to this feature or documentation about it? I see vary raw documentation in the sample CIS benchark policy audit files, but leaves me guessing about some of it? I want to write the policy for the

Re: [ossec-list] Re: OSSEC + CIS benchmark tests

2015-05-15 Thread dan (ddp)
On May 15, 2015 5:27 PM, The O.G. theoriginalg...@gmail.com wrote: So, does that mean the best way to understand how the system policy audit works is to basically read the source code in rootcheck system? It simply means I cannot answer many questions about it. Reading the aource is one way to

Re: [ossec-list] Re: OSSEC + CIS benchmark tests

2015-05-15 Thread The O.G.
So, does that mean the best way to understand how the system policy audit works is to basically read the source code in rootcheck system? On Fri, May 15, 2015 at 5:04 AM, dan (ddp) ddp...@gmail.com wrote: On Tue, May 12, 2015 at 6:57 PM, autodidactic theoriginalg...@gmail.com wrote: Are

[ossec-list] Re: OSSEC + CIS benchmark tests

2015-05-12 Thread autodidactic
Are there any updates to this feature or documentation about it? I see vary raw documentation in the sample CIS benchark policy audit files, but leaves me guessing about some of it? I want to write the policy for the newer CIS benchmarks for EL6 and EL7... any help or pointers to where I can