Hi,

I am consolidating my logs using syslog-ng and have OSSEC v2.5.1 deployed on
the main syslog server for log analysis.   OSSEC is installed in local mode
and is setup to analyse the consolidated log file.

When I make any config changes to OSSEC and restart analysisd/logcollector,
there is a small duration of time during which the log file is potentially
not monitored.

My question is
1.  Does OSSEC keep a track of its position in the log file, so that when I
restart it, logcollector will start from the position it stopped.
2.  If not, is there any way I can make configuration changes "on-the-fly"
without bringing down the OSSEC server
3.  If #2 is not possible, is there any way to configure a failover with a
second instance of an OSSEC server

Regards,
Chris

Reply via email to