Hi Aaron, This was a bug that we fixed for version 2.0. You can try the fix with our latest snapshot:
http://ossec.net/files/snapshots/ossec-hids-090220.tar.gz Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Wed, Oct 29, 2008 at 11:58 AM, Aaron Bliss <[email protected]> wrote: > Hi all, > I'm not sure if I'm running the tool properly, however here is what I'm > doing: > > ./rootcheck_control -l | grep bantest > ID: 069, Name: bantest, IP: 137.21.6.50, Active > > ./rootcheck_control -q -i 069 > Policy and auditing events for agent 'bantest (069) - 137.21.8.3': > > It doesn't seem to matter what agent id I use, the IP address when passing > rootcheck_control -q -i switches stays the same. The IP address printed > using the -l switch is correct. From the best I can tell, the printed > outstanding issues for the agent is correct. Server and agent are both > running ossec 1.6.1 > > Aaron >
