Wow, very nice. I'm amazed I haven't seen that feature before. I read the 
sygress book and it made no mention of that feature.

Excellent stuff, I greatly appreciate the response. I'll check it out read up. 
Sorry to add white noise to the list.

-Tim Eberhard

On Oct 9, 2010, at 1:55 PM, "[email protected]" <[email protected]> wrote:

> Oops, I meant the report_changes option in syscheck, check_diff is different.
> 
> 
> -----Original Message-----
> From: Tim Eberhard
> Sent:  10/09/2010 12:15:51 PM
> Subject:  [ossec-list] dev roadmap?
> 
> All,
> 
> I hate to ask such a basic question but after browsing/googling I have been
> unable to find any kind of documented roadmap for OSSEC.
> 
> Of course I had a few specific features in mind that I wanted to see if were
> on the roadmap.
> 
> I searched the archive and I've found a few of them have been asked in the
> past. The primary feature I'm looking for is the central repo/diff
> capability for configuration files built into ossec. When evaluating OSSEC
> vs some commercial alternatives some of the short comings we found were
> mainly around the ability to track/alert on not only signature changes to
> files but evaluate the configuration file and answer the commonly asked
> question "great the md5 signature changed.. but WHAT changed?"
> 
> I know you can hack something up with some active response combo with a
> change repo but that really isn't a decent solution that integrates with
> OSSEC.
> 
> Thanks for your help, sorry if I missed the obvious.
> -Tim Eberhard
> 

Reply via email to