On Wed, 27 Oct 2010 14:25:25 -0400 "dan (ddp)" <[email protected]> wrote:
> What's the worst that will happen if you try it? I can give it a try :) I'm just afraid that it may break OSSEC system. > You're using an ancient version, in a strange configuration. I'm not > sure how many people will be able to test something like this and > get back to you. Give it a shot. If it breaks, you should know how > to fix it. ;) When I use the latest version of OSSEC (2.5.1) I have the same problem. My system is too old: it's Debian Lenny and it is running on Amazon platform (http://aws.amazon.com/). That's why I can't upgrade my FUSE module :( Thank you for your helps. > > On Tue, Oct 26, 2010 at 8:41 PM, Anh K. Huynh <[email protected]> > wrote: > > Hi, > > > > I am using ossec-1.6.5 on a distributed file system which doesn't > > support group (actually, this is due to an old version of FUSE > > module.) Therefore the file "/queue/alerts/execq" is accessible > > by its group: > > > > /====================================================== > > cd /opt/ossec.agent.osxcad0/queue/alerts && ls -ltr > > total 0 > > srw-rw---- 1 root ossec 0 2010-10-25 02:57 execq= > > \====================================================== > > > > On agents, there's only "ossec" user. Can I update the owner of > > that file, by "chown ossec:ossec execq"? If "yes", can the same > > method be applied on Ossec's master? > > > > Thank your for your helps, > > > > -- > > Anh Ky Huynh > > -- Anh Ky Huynh
