Hi.

I'm using ossec to monitor some windows agents on 2003 server.

The server is running centos and saving the information in a mysql database.

When I receive a syscheck event from windows (file modified, deleted or 
added) the username is empty. 

Is it possible to modify some rule to have that username logged on the 
event ?

Thanks a lot.

Reply via email to