I only do this at home, so official processes are lacking at best. But
I use a CVS repository to keep track of configs and rules.
When I get around to setting up puppet again, I plan on using that to
help maintain the ossec installs a bit.
Also when I get some time I want to clean up my local rules and post a
few of them...

On Wed, Jun 24, 2009 at 11:16 PM, JM<[email protected]> wrote:
>
> On Tue, Jun 23, 2009 at 05:40, Raghu GS<[email protected]> wrote:
>>
>> You can configure OSSEC-HIDS to add all the events to database.
>>
>> On Jun 20, 11:15 pm, JM <[email protected]> wrote:
>>> I'm looking for some advice on methods used to document local rules or
>>> rule changes in your environment.
>>>
>>> Do you just use a spreadsheet?  Or do you check the config files into
>>> an SVN,git, or CVS repository?  How do you track & authorize changes
>>> (if at all?)
>>>
>
> That works for events, but not configuration or versioning....
>
> so....no one does this?
>
> JM
>

Reply via email to