A file integrity check is needed on archived files only. For instance, /var/log/httpd/*.gz. How is this possible? And can the rule(s) be set up on the ossec server rather than the clients?
- [ossec-list] File integrity check needed on archived logs helpmailinglist
