I imagine there might be difficulties with udev or devfs or whatever linux is using now. Haven't tried it though.
On Fri, Mar 12, 2010 at 11:33 AM, Devendra Agrawal <[email protected]> wrote: > By default, ossec doesn't seems to be doing file integrity checks for /dev, > /boot, and hidden files (starting with ".") on Linux. Can ossec monitor them > reliably (if I add them in ossec.conf)? I am not sure if there is any > advantage in doing the same check for /proc too. > > Thanks.
