defined-agent is working for me. Except in the case where the logs are
monitored on the manager (example: ssh brute force attack against the
manager itself). I think this matches up with the behavior you were
describing.

Not sure why it works this way though.

On Thu, Feb 10, 2011 at 6:52 PM, Jeremy Lee <[email protected]> wrote:
> Reading through that again, that was pretty confusing...!! BTW: I meant to
> say "attackers.log" in scenario A) where I am saying "On ORANGE, I have
> confirmed that I am watching..."
>
>
> I think this issue might have already been noticed by someone else:
> http://www.mail-archive.com/[email protected]/msg07135.html
>
>
> I think the interim solutions will be to ship the logs to another agent w/
> the OSSEC agent and do it that way. Or I can just go with scenario B. My
> concern is that I don't want to add load to the server as we've had issues
> with OSSEC on this box before.
>

Reply via email to