Hi Rob,

You can backup the whole /var/ossec directory and just copy it back
after the server
is reinstalled. However, if you change the server IP address or the
operating system,
you can run into some other problems (binary incompatibility, etc). In
this case, I would suggest to just backup /var/ossec/etc/ossec.conf ,
/var/ossec/etc/client.keys (where the
agents are stored) and /var/ossec/rules (if you have local rules). You
may also want to backup /var/ossec/logs to keep your old alerts. If
you choose the second option, just
do a clean installed and copy these files after.

*Note that if you change the ip address of the server, you will need
to change the
server-ip on the agents too.

Hope it helps.

--
Daniel B. Cid
dcid ( at ) ossec.net

On 6/4/07, Rob <[EMAIL PROTECTED]> wrote:
> Hey all, congrats with the new release.  I have a few quick questions.  The
> VM that is running my ossec server install is having issues and probably
> will need a rebuild.  So, can I merely backup the directories that have
> ossec and then copy them back after the rebuild is done?  Or will I need
> reinstall everything, including the agents?  I'd rather not reinstall the
> agents if at all, entering the keys was a pain...
>
>
>
> Thanks,
> Robert
>

Reply via email to