On Tue, Jul 31, 2012 at 11:01 PM, Patrick <[email protected]> wrote: > Hi, > > We're looking at OSSEC and I'm wondering if it supports the following config > Ossec Agent -> Ossec Server -> Ossec Server? > > We have multiple LAN segments and want to have a central OSSEC aggregation > point in each segment, then have that aggregation point forward logs to a > central OSSEC server. > > I already have OSSEC agents talking to their respective OSSEC agg point in > their zone, however need assistance getting the agg points talking to the > final OSSEC server. > > Is this supported/achievable? > > Thank you for any info you can provide. > > Pat
The latest development code has a "hybrid" mode, which is a combination server + agent. It's intended use is for this type of setup.
