On Mon, Jan 10, 2011 at 5:37 PM, Michael Starks
<[email protected]> wrote:
> On Mon, 10 Jan 2011 17:32:09 -0500, "dan (ddp)" <[email protected]> wrote:
>>
>> Hi Andy,
>>
>> On Mon, Jan 10, 2011 at 5:18 PM, NetSyphon <[email protected]> wrote:
>>>
>>> Hello List,
>>> Does OSSEC do any sort of log replay on either windows or *nix, so that
>>> if
>>> an agent is stopped and started that it will "replay" to catch up?  I'm
>>> trying to prove that OSSEC is at least a better option than something
>>> like
>>> syslogd/SNARE/logparser for log centralization (and in many cases better
>>> than overpriced and bloated solutions from vendors like arcsight, if
>>> there
>>> was only a more robust front end!).
>>>
>>> TIA,
>>> Andy
>>>
>>>
>>
>> The agents keep track of where in the logfiles they stop. So if the
>> ossec processes were stopped and started again a while later they
>> should pick up where they left off.
>
> I'm not sure this is true, at least for Windows. I have observed different
> behavior but it was awhile back and I didn't have time to pursue it. I think
> this is worth validating.
>
> --
> Michael Starks
> [I] Immutable Security
> http://www.immutablesecurity.com
>

You might be right. I just re-read over Daniel Cid's responses to the
following thread, and I'm definitely not sure how Windows handles it:
http://marc.info/?l=ossec-list&m=126632282723634&w=2

Reply via email to