Greetings Andy: If the upgrade works like previous upgrades, you can go directly from 1.4 to 1.6
NOTES: custom rules should be in rules/local_rules.xml; and if you've done that, then they are safe. If the 1.6 upgrade works like previous ones, some customizations to ossec.conf (typically in /var/ossec/etc/) can be lost such as the area of what rules to exclude. So it is best to backup ossec.conf and then compare the results after the upgrade. Also, while I believe 1.6 has a way to protect custom decoders (like local rules), 1.5 and prior did not; so if you have any decoder changes, back those up and then update as appropriate in 1.6 (i.e. local or custom decoder file -- I don't know the nomenclature at this time). Thank you.
