Thanks for the info. We would like a second layer as we do not currently permit the outer DMZ to communicate directly with the internal segment where the final OSSEC server will reside. Also we are planning on expanding our operations and this hierarchy will allow us to have remote OSSEC server for local collection and reporting if necessary.
On Wednesday, August 1, 2012 1:01:09 PM UTC+10, Patrick wrote: > > Hi, > > We're looking at OSSEC and I'm wondering if it supports the following > config Ossec Agent -> Ossec Server -> Ossec Server? > > We have multiple LAN segments and want to have a central OSSEC aggregation > point in each segment, then have that aggregation point forward logs to a > central OSSEC server. > > I already have OSSEC agents talking to their respective OSSEC agg point in > their zone, however need assistance getting the agg points talking to the > final OSSEC server. > > Is this supported/achievable? > > Thank you for any info you can provide. > > Pat >
