Hi, I came across a couple threads mentioning it's impossible to have OSSEC point to another logging directory due to "chrooted processes" - this seems a bit convoluted and I just wanted to know practically *why* it isn't possible and if there are any thoughts on bringing the option in (and if not, why not).
I don't see any reason why it would be a bad idea to be able to log to another location. I know the OSSEC logs don't grow very large, but this dynamic can change if many clients are added that are generally noisier (depending on how the alerting is setup). Regardless, it would just be nice to have the option. I know there are several workarounds: mounting a new partition and assigning it /var/ossec/logs, but that can be quite a hassle depending on the environment and won't work for everyone. The only other option is rsyncing files over, but that's more overhead to be concerned about.
