On Wed, Jul 1, 2009 at 4:21 PM, Peter M. Abraham<[email protected]> wrote: > > Greetings: > > /var/ossec/etc/ossec.conf is overwritten on the server (I think it is > safe on agents). > > If you've commented out rules; you will need to redo all of that work > (which is lost from every upgrade from the 1.x days until 2.1 > inclusive). > > thank you. >
Most changes seemed to be saved between versions on the server. I wonder why the rules list is overwritten.
