It's new in 2.5. Update to 2.5.1 (the latest) and you'll have it and a few other neat features.
-----Original Message----- From: Tim Eberhard Sent: 10/09/2010 3:17:23 PM Subject: Re: [ossec-list] dev roadmap? Wow, very nice. I'm amazed I haven't seen that feature before. I read the sygress book and it made no mention of that feature. Excellent stuff, I greatly appreciate the response. I'll check it out read up. Sorry to add white noise to the list. -Tim Eberhard On Oct 9, 2010, at 1:55 PM, "[email protected]" <[email protected]> wrote: > Oops, I meant the report_changes option in syscheck, check_diff is different. > > > -----Original Message----- > From: Tim Eberhard > Sent: 10/09/2010 12:15:51 PM > Subject: [ossec-list] dev roadmap? > > All, > > I hate to ask such a basic question but after browsing/googling I have been > unable to find any kind of documented roadmap for OSSEC. > > Of course I had a few specific features in mind that I wanted to see if were > on the roadmap. > > I searched the archive and I've found a few of them have been asked in the > past. The primary feature I'm looking for is the central repo/diff > capability for configuration files built into ossec. When evaluating OSSEC > vs some commercial alternatives some of the short comings we found were > mainly around the ability to track/alert on not only signature changes to > files but evaluate the configuration file and answer the commonly asked > question "great the md5 signature changed.. but WHAT changed?" > > I know you can hack something up with some active response combo with a > change repo but that really isn't a decent solution that integrates with > OSSEC. > > Thanks for your help, sorry if I missed the obvious. > -Tim Eberhard >
