Hello everyone,
I have a centralized agent configuration and some question about them.
1) Rules on agent ossec.conf and server agent.conf are merged?
2) If not what config are main and what are ignore?
3) What happened if i put next rules on d:\ossec-agent\ossec.conf
<directories check_all=yes>d:\test</directories>
<directories check_all=yes>d:\test2</directories>
and this in /var/ossec/etc/shared/agent.conf for this agent
<ignore>d:\test\info</ignore>
<ignore>d:\test2</ignore>
Best regards,
Urban Mikhail