I only do this at home, so official processes are lacking at best. But I use a CVS repository to keep track of configs and rules. When I get around to setting up puppet again, I plan on using that to help maintain the ossec installs a bit. Also when I get some time I want to clean up my local rules and post a few of them...
On Wed, Jun 24, 2009 at 11:16 PM, JM<[email protected]> wrote: > > On Tue, Jun 23, 2009 at 05:40, Raghu GS<[email protected]> wrote: >> >> You can configure OSSEC-HIDS to add all the events to database. >> >> On Jun 20, 11:15 pm, JM <[email protected]> wrote: >>> I'm looking for some advice on methods used to document local rules or >>> rule changes in your environment. >>> >>> Do you just use a spreadsheet? Or do you check the config files into >>> an SVN,git, or CVS repository? How do you track & authorize changes >>> (if at all?) >>> > > That works for events, but not configuration or versioning.... > > so....no one does this? > > JM >
