Hi,

I came across a couple threads mentioning it's impossible to have
OSSEC point to another logging directory due to "chrooted processes" -
this seems a bit convoluted and I just wanted to know practically
*why* it isn't possible and if there are any thoughts on bringing the
option in (and if not, why not).

I don't see any reason why it would be a bad idea to be able to log to
another location. I know the OSSEC logs don't grow very large, but
this dynamic can change if many clients are added that are generally
noisier (depending on how the alerting is setup). Regardless, it would
just be nice to have the option.

I know there are several workarounds: mounting a new partition and
assigning it /var/ossec/logs, but that can be quite a hassle depending
on the environment and won't work for everyone. The only other option
is rsyncing files over, but that's more overhead to be concerned
about.

Reply via email to