Hi,

I have recently starting to test OSSEC with intention to deploy in our
datacentres. I would like to have integrity checks every hour (at
least on the most critical systems) and I am wondering how this would
play with the speed throttling implemented in the scanning agent.
Basically what will happen if the agent does not finish a scan
(because it takes longer that one hour) and the manager order a new
one?

It would be ideal to know when OSSEC starts and finish every integrity
check on a per agent bases (is there a specific queue for feature
requests?). This information would help an admin to tune the scan
speed (using the syscheck.sleep* options) and will help to understand
how long a change would go unnoticed.

Thanks for your assistance and keep up the good work.

--Marco

Reply via email to