On Tue, Jun 8, 2010 at 8:14 PM, dp <[email protected]> wrote: > On Jun 8, 5:27 am, "dan (ddp)" <[email protected]> wrote: > >> 2. Every client gets the entire agent.conf, and only uses the parts >> that apply to that system. > > Does that mean it's strictly additive, so that checks already defined > in a client's ossec.conf cannot be removed by omission from server's > agent.conf? > For auditing purposes I really need to see the config as the client > does.
Correct. The ossec.conf and agent.conf (the parts that apply to that system) are combined.
