You should put all the config in shared/agent.conf your ossec.conf on the
sensors/agents should be as minimal as <server>xx.xxxx.xxx.x</server>

On Mon, Jun 6, 2011 at 2:50 PM, Christopher Moraes <[email protected]>wrote:

> Hi Frank,
>
> If I create an agent.conf file on the server, will it overwrite the
> settings of the agent's local ossec.conf or are the two configs merged in
> some way?
>
>
> On Mon, Jun 6, 2011 at 6:29 AM, Frank Stefan Sundberg Solli <
> [email protected]> wrote:
>
>> Hi.
>>
>> The file can be found in shared/agent.conf
>>
>>
>> On Mon, Jun 6, 2011 at 3:42 AM, treydock <[email protected]> wrote:
>>
>>> What settings from the OSSEC server's etc/ossec.conf file are used to
>>> on the clients?  For example I've defined rules and active responses
>>> on my server, and they are working fine, but what about <localfile>
>>> items?  Is there a way to centrally define what local files an agent
>>> should be checking, or would this be the case where something like
>>> Puppet comes into play?  I have this on my server, and it works, but
>>> just realized I probably need to push this to my clients,
>>>
>>>
>>>  <localfile>
>>>    <log_format>syslog</log_format>
>>>    <location>/var/ossec/logs/active-responses.log</location>
>>>  </localfile>
>>>
>>> Thanks
>>> - Trey
>>
>>
>>
>>
>> --
>> MVH/With regards
>>
>> Frank
>> --
>> Name:         Frank Stefan Sundberg Solli
>> E-mail:         [email protected]
>> Web:            http://fssol.blogspot.com
>> GPG:            684119F4
>>
>>
>


-- 
MVH/With regards

Frank
--
Name:         Frank Stefan Sundberg Solli
E-mail:         [email protected]
Web:            http://fssol.blogspot.com
GPG:            684119F4

Reply via email to