On Mon, Jan 10, 2011 at 5:37 PM, Michael Starks <[email protected]> wrote: > On Mon, 10 Jan 2011 17:32:09 -0500, "dan (ddp)" <[email protected]> wrote: >> >> Hi Andy, >> >> On Mon, Jan 10, 2011 at 5:18 PM, NetSyphon <[email protected]> wrote: >>> >>> Hello List, >>> Does OSSEC do any sort of log replay on either windows or *nix, so that >>> if >>> an agent is stopped and started that it will "replay" to catch up? I'm >>> trying to prove that OSSEC is at least a better option than something >>> like >>> syslogd/SNARE/logparser for log centralization (and in many cases better >>> than overpriced and bloated solutions from vendors like arcsight, if >>> there >>> was only a more robust front end!). >>> >>> TIA, >>> Andy >>> >>> >> >> The agents keep track of where in the logfiles they stop. So if the >> ossec processes were stopped and started again a while later they >> should pick up where they left off. > > I'm not sure this is true, at least for Windows. I have observed different > behavior but it was awhile back and I didn't have time to pursue it. I think > this is worth validating. > > -- > Michael Starks > [I] Immutable Security > http://www.immutablesecurity.com >
You might be right. I just re-read over Daniel Cid's responses to the following thread, and I'm definitely not sure how Windows handles it: http://marc.info/?l=ossec-list&m=126632282723634&w=2
