Hi Peter,

It can go to the ossec.conf or to the centralized agent.conf as well.
Both will work. Currently there is
no way to control how often they run, but that might be a good feature
to add. Right now it is every
1 or 2 minutes (depending on the flow of the logs).

Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net

On Mon, Dec 7, 2009 at 3:10 PM, Peter M. Abraham
<[email protected]> wrote:
> Greetings:
>
> RE:  http://www.ossec.net/main/manual/manual-process-monitoring/
>
> 1.  Does the syntax for the command line processing need to go in each
> agent ossec.conf file or can it be in the centralized server
> ossec.conf file?
>
> i.e. would I place
>
>        <localfile>
>            <log_format>command</log_format>
>
>             <command>uptime</command>
>         </localfile>
>
> In the server or on the agent in the ossec.conf file?
>
> 2.  How often are the commands run?  Is there a way to control how
> often the commands are run?
>
> Thank you.
>

Reply via email to