I tried to follow the 
http://www.ossec.net/doc/manual/agent/agent-configuration.html manual but 
agents doesn't get the configuration from shared directory 
(/var/ossec/etc/shared directory on server).

пятница, 12 октября 2012 г., 10:46:38 UTC+4 пользователь kay kay написал:
>
> At the moment I use syslog-ng to collect logs from whole servers and 
> analyze them on ossec-server with decoders and rules.
>
> How can I configure ossec-server to avoid log collecting with syslog-ng?
>
> I.e. I have two servers (ossec-agents) with nginx. I need to analyze nginx 
> logs. Should I configure decoder and rule on each ossec-agents or I can 
> create one decoder and one rule on ossec-server and it will be 
> automatically pushed to ossec-agents?
>

Reply via email to