All,
Apologies if this has been covered, but I sure couldn't find it :-)
In my lab I have a central ossec 2.6 server on Ubuntu and one client on
Centos, set them up with active response and followed procedure here:
http://www.ossec.net/doc/manual/agent/agent-configuration.html
agent.conf is written to the client upon restart of server and client
ossec.conf is not overwritten
This feels like a permissions error, agent.conf is owned by ossec:ossec and
ossec.conf is owned by root:root and is not writable by other than root,
this is default as far as I can tell and I don't want to muck with it
unless I have to.
Any help would be...helpful :-)
-Thanks