|
Micheal,
I have not yet crossed that bridge, but thinking about it ...
Sharing rules between OSSEC servers could boil down to distribution/syncronization of a single file: /var/ossec/rules/local_rules.xml . But that would still require a manual server "restart" to read it.
How about using a wrapper script when editing local_rules.xml, that also performs an scp and ssh ...restart ?
KenW
From: [email protected] [[email protected]] On Behalf Of Michael Altfield [[email protected]] Sent: Wednesday, August 05, 2009 12:49 PM To: [email protected] Subject: [ossec-list] Re: Agent alert queues to prevent data loss Hi Ken,
Thanks for your input. I currently have this setup pointing the OSSEC Manager to Splunk. It works great. Still, having 2 OSSEC Managers, every time you have to update a rule, you have to do so twice, correct? Did you find a good way around this? -Michael On Wed, Aug 5, 2009 at 11:12 AM, Ken Wachtler
<[email protected]> wrote:
|
- [ossec-list] Agent alert queues to prevent data loss Michael Altfield
- [ossec-list] Re: Agent alert queues to prevent data ... Ken Wachtler
- [ossec-list] Re: Agent alert queues to prevent d... Michael Altfield
- [ossec-list] Re: Agent alert queues to preve... Michael Altfield
- [ossec-list] Re: Agent alert queues to p... ddp
- [ossec-list] Re: Agent alert queues to p... Ken Wachtler
- [ossec-list] Re: Agent alert queues... Michael Altfield
- [ossec-list] Re: Agent alert qu... Ken Wachtler
- [ossec-list] Re: Agent alert qu... Michael Starks
- [ossec-list] Re: Agent alert queues to prevent data ... Daniel Cid
