Hi, I am consolidating my logs using syslog-ng and have OSSEC v2.5.1 deployed on the main syslog server for log analysis. OSSEC is installed in local mode and is setup to analyse the consolidated log file.
When I make any config changes to OSSEC and restart analysisd/logcollector, there is a small duration of time during which the log file is potentially not monitored. My question is 1. Does OSSEC keep a track of its position in the log file, so that when I restart it, logcollector will start from the position it stopped. 2. If not, is there any way I can make configuration changes "on-the-fly" without bringing down the OSSEC server 3. If #2 is not possible, is there any way to configure a failover with a second instance of an OSSEC server Regards, Chris
