You need to clarify, are these servers agents? If so then you need to look into config-profile for the agent configuration. Define different profiles in the manager's /var/ossec/etc/shared/agent.conf and specify the appropriate profile for the agent it it's ossec.conf using config-profile.
On Tuesday, November 14, 2017 at 7:53:56 AM UTC-6, amar haq wrote: > > Dear All > > Could OSSEC perform syscheck for File Integration Monitoring on specific > agent. let's say I have 5 servers.Server A,B,C,D,E. > on server A , I just want to monitor /var/www/html/Demo/demo.db. > on server B, i want to monitor only /ngingx/index.html. > on Server C, i want to monitor /var/www/html/XYZ.xx, etc > > > could you help me? because I read that Active rsponse have <agent_id> tag > to define specific agent. > > thankyou. > Amar. > > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.