Greetings Andy:

If the upgrade works like previous upgrades, you can go directly from
1.4 to 1.6

NOTES:

custom rules should be in rules/local_rules.xml; and if you've done
that, then they are safe.

If the 1.6 upgrade works like previous ones, some customizations to
ossec.conf (typically in /var/ossec/etc/) can be lost such as the area
of what rules to exclude.  So it is best to backup ossec.conf and then
compare the results after the upgrade.

Also, while I believe 1.6 has a way to protect custom decoders (like
local rules), 1.5 and prior did not; so if you have any decoder
changes, back those up and then update as appropriate in 1.6 (i.e.
local or custom decoder file -- I don't know the nomenclature at this
time).

Thank you.

Reply via email to