Dear Sir/Madam,

I deployed OSSEC as a HIDS agent to a big old system (SUSE 9 without
inotify) in our company. Being required by my boss, it is essential
for me to report critical file changes ASAP to various system owners.

With the limitation, I decided to use frequent syscheck to replace the
real-time features. I set the frequency to <frequency>900</frequency>,
I have also disabled the auto-ignore feature. However, it is
discovered that the file change event appears 30 minutes later, or
even not showing up. I have checked that the database is not empty by
using ossec-wui. Is there any configuration error I have made?

Best Regards,
Sun

Reply via email to