Dear Sir/Madam, I deployed OSSEC as a HIDS agent to a big old system (SUSE 9 without inotify) in our company. Being required by my boss, it is essential for me to report critical file changes ASAP to various system owners.
With the limitation, I decided to use frequent syscheck to replace the real-time features. I set the frequency to <frequency>900</frequency>, I have also disabled the auto-ignore feature. However, it is discovered that the file change event appears 30 minutes later, or even not showing up. I have checked that the database is not empty by using ossec-wui. Is there any configuration error I have made? Best Regards, Sun
