defined-agent is working for me. Except in the case where the logs are monitored on the manager (example: ssh brute force attack against the manager itself). I think this matches up with the behavior you were describing.
Not sure why it works this way though. On Thu, Feb 10, 2011 at 6:52 PM, Jeremy Lee <[email protected]> wrote: > Reading through that again, that was pretty confusing...!! BTW: I meant to > say "attackers.log" in scenario A) where I am saying "On ORANGE, I have > confirmed that I am watching..." > > > I think this issue might have already been noticed by someone else: > http://www.mail-archive.com/[email protected]/msg07135.html > > > I think the interim solutions will be to ship the logs to another agent w/ > the OSSEC agent and do it that way. Or I can just go with scenario B. My > concern is that I don't want to add load to the server as we've had issues > with OSSEC on this box before. >
