Hi Peter, It can go to the ossec.conf or to the centralized agent.conf as well. Both will work. Currently there is no way to control how often they run, but that might be a good feature to add. Right now it is every 1 or 2 minutes (depending on the flow of the logs).
Thanks, -- Daniel B. Cid dcid ( at ) ossec.net On Mon, Dec 7, 2009 at 3:10 PM, Peter M. Abraham <[email protected]> wrote: > Greetings: > > RE: http://www.ossec.net/main/manual/manual-process-monitoring/ > > 1. Does the syntax for the command line processing need to go in each > agent ossec.conf file or can it be in the centralized server > ossec.conf file? > > i.e. would I place > > <localfile> > <log_format>command</log_format> > > <command>uptime</command> > </localfile> > > In the server or on the agent in the ossec.conf file? > > 2. How often are the commands run? Is there a way to control how > often the commands are run? > > Thank you. >
