Hi Rob, You can backup the whole /var/ossec directory and just copy it back after the server is reinstalled. However, if you change the server IP address or the operating system, you can run into some other problems (binary incompatibility, etc). In this case, I would suggest to just backup /var/ossec/etc/ossec.conf , /var/ossec/etc/client.keys (where the agents are stored) and /var/ossec/rules (if you have local rules). You may also want to backup /var/ossec/logs to keep your old alerts. If you choose the second option, just do a clean installed and copy these files after.
*Note that if you change the ip address of the server, you will need to change the server-ip on the agents too. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On 6/4/07, Rob <[EMAIL PROTECTED]> wrote: > Hey all, congrats with the new release. I have a few quick questions. The > VM that is running my ossec server install is having issues and probably > will need a rebuild. So, can I merely backup the directories that have > ossec and then copy them back after the rebuild is done? Or will I need > reinstall everything, including the agents? I'd rather not reinstall the > agents if at all, entering the keys was a pain... > > > > Thanks, > Robert >
