Hello List, Does OSSEC do any sort of log replay on either windows or *nix, so that if an agent is stopped and started that it will "replay" to catch up? I'm trying to prove that OSSEC is at least a better option than something like syslogd/SNARE/logparser for log centralization (and in many cases better than overpriced and bloated solutions from vendors like arcsight, if there was only a more robust front end!).
TIA, Andy
