So what is the difference, between say, the parameter
in the ossec.conf file on the Server and the agent.conf file that
eventually gets uploaded to the Agent? I was under the impression that the
frequency setting in ossec.conf would be used locally if the Server were
performing syschecks on
That goes on the manager ossec.conf
The manager takes care of analyzing syscheck data received from the agents, and
generate alerts.
I hope it helps
Santiago Bassett
@santiagobassett
> On Feb 23, 2018, at 9:59 AM, temp.email@gmail.com wrote:
>
> Hi Santiago, I just came across your post.
Hi Santiago, I just came across your post. Are you saying that the
auto_ignore and alert_new_files goes in /var/ossec/etc/ossec.conf on the
manager OR in /var/ossec/etc/shared/agent.conf on the manager? Obviously,
the latter will eventually be placed on the Agent. I thought that
Are you using scan_on_start option? Remember realtime won't work until
first syscheck is done.
I also recommend to use alert_new_files and set auto_ignore to "no" (this
goes on the manager).
Useful trobleshooting tip is to enable debug for syscheck on the agent
(internal_options.conf file)
Best