I'm also trying to push <scan_on_start>no</scan_on_start> via
agent.conf and it seems like this also is not working.

I commented out the "frequency" flag in ossec.conf as well and
restarted the OSSEC agent on a couple servers but within minutes, the
syscheck/rootcheck scans kicked off. I verified that the agent.conf
with the <scan_on_start> set to "no" flag is present as well.



On Sep 28, 11:20 am, "dan (ddp)" <[email protected]> wrote:
> On Tue, Sep 28, 2010 at 1:31 PM, Jeremy Lee <[email protected]> wrote:
> > That makes sense. I guess what I'd really want to see the option to
> > push/update just a single 'config' file (ossec.conf) to all clients :)
>
> If the only configuration you do in the ossec.conf is the server IP,
> then pushing out the agent.conf is basically what you're asking for.

Reply via email to