Hi, I have recently starting to test OSSEC with intention to deploy in our datacentres. I would like to have integrity checks every hour (at least on the most critical systems) and I am wondering how this would play with the speed throttling implemented in the scanning agent. Basically what will happen if the agent does not finish a scan (because it takes longer that one hour) and the manager order a new one?
It would be ideal to know when OSSEC starts and finish every integrity check on a per agent bases (is there a specific queue for feature requests?). This information would help an admin to tune the scan speed (using the syscheck.sleep* options) and will help to understand how long a change would go unnoticed. Thanks for your assistance and keep up the good work. --Marco
