Thanks sweet, thanks again guys. Amazing work. I would still love to see a roadmap posted just to see what cool new stuff is getting worked on. Just tossing that out there :)
-Tim Eberhard On Oct 9, 2010, at 5:20 PM, Daniel Cid <[email protected]> wrote: > It is a new feature added on v2.5, so not available during the write > of the book. > > Just add report_changes="yes" to add monitored directory and you will get > the "diff" between versions. > > Thanks, > > On Sat, Oct 9, 2010 at 4:17 PM, Tim Eberhard <[email protected]> wrote: >> Wow, very nice. I'm amazed I haven't seen that feature before. I read the >> sygress book and it made no mention of that feature. >> >> Excellent stuff, I greatly appreciate the response. I'll check it out read >> up. Sorry to add white noise to the list. >> >> -Tim Eberhard >> >> On Oct 9, 2010, at 1:55 PM, "[email protected]" <[email protected]> wrote: >> >>> Oops, I meant the report_changes option in syscheck, check_diff is >>> different. >>> >>> >>> -----Original Message----- >>> From: Tim Eberhard >>> Sent: 10/09/2010 12:15:51 PM >>> Subject: [ossec-list] dev roadmap? >>> >>> All, >>> >>> I hate to ask such a basic question but after browsing/googling I have been >>> unable to find any kind of documented roadmap for OSSEC. >>> >>> Of course I had a few specific features in mind that I wanted to see if were >>> on the roadmap. >>> >>> I searched the archive and I've found a few of them have been asked in the >>> past. The primary feature I'm looking for is the central repo/diff >>> capability for configuration files built into ossec. When evaluating OSSEC >>> vs some commercial alternatives some of the short comings we found were >>> mainly around the ability to track/alert on not only signature changes to >>> files but evaluate the configuration file and answer the commonly asked >>> question "great the md5 signature changed.. but WHAT changed?" >>> >>> I know you can hack something up with some active response combo with a >>> change repo but that really isn't a decent solution that integrates with >>> OSSEC. >>> >>> Thanks for your help, sorry if I missed the obvious. >>> -Tim Eberhard >>> >>
