Hi. I'm using ossec to monitor some windows agents on 2003 server.
The server is running centos and saving the information in a mysql database. When I receive a syscheck event from windows (file modified, deleted or added) the username is empty. Is it possible to modify some rule to have that username logged on the event ? Thanks a lot.
