It is a new feature added on v2.5, so not available during the write
of the book.

Just add report_changes="yes" to add monitored directory and you will get
the "diff" between versions.

Thanks,

On Sat, Oct 9, 2010 at 4:17 PM, Tim Eberhard <[email protected]> wrote:
> Wow, very nice. I'm amazed I haven't seen that feature before. I read the 
> sygress book and it made no mention of that feature.
>
> Excellent stuff, I greatly appreciate the response. I'll check it out read 
> up. Sorry to add white noise to the list.
>
> -Tim Eberhard
>
> On Oct 9, 2010, at 1:55 PM, "[email protected]" <[email protected]> wrote:
>
>> Oops, I meant the report_changes option in syscheck, check_diff is different.
>>
>>
>> -----Original Message-----
>> From: Tim Eberhard
>> Sent:  10/09/2010 12:15:51 PM
>> Subject:  [ossec-list] dev roadmap?
>>
>> All,
>>
>> I hate to ask such a basic question but after browsing/googling I have been
>> unable to find any kind of documented roadmap for OSSEC.
>>
>> Of course I had a few specific features in mind that I wanted to see if were
>> on the roadmap.
>>
>> I searched the archive and I've found a few of them have been asked in the
>> past. The primary feature I'm looking for is the central repo/diff
>> capability for configuration files built into ossec. When evaluating OSSEC
>> vs some commercial alternatives some of the short comings we found were
>> mainly around the ability to track/alert on not only signature changes to
>> files but evaluate the configuration file and answer the commonly asked
>> question "great the md5 signature changed.. but WHAT changed?"
>>
>> I know you can hack something up with some active response combo with a
>> change repo but that really isn't a decent solution that integrates with
>> OSSEC.
>>
>> Thanks for your help, sorry if I missed the obvious.
>> -Tim Eberhard
>>
>

Reply via email to