On Jul 17, 2013 3:16 PM, "bunnyfuzzypink" <[email protected]> wrote: > > Hi Dan, > > Thank you for the fast response. I am unable to locate in the documentation or by google search a method to disable the OSSEC agent from reading the local machine's log files. I have tried creating the following in the agent file: > > <localfile> > </localfile> > >
I would try removing the localfile config blocks, and possibly remove ossec-logcollector from ossec-control. > Thanks > > Tony > > On Wednesday, July 17, 2013 2:55:51 PM UTC-4, dan (ddpbsd) wrote: >> >> >> On Jul 17, 2013 2:54 PM, "bunnyfuzzypink" <[email protected]> wrote: >> > >> > Hello OSSEC list, >> > >> > Is it possible to disable the OSSEC agent from reading the local machine's logs? >> > >> >> Yep, should be possible. Are you having issues? >> >> > Thanks >> > >> > >> > -- >> > >> > --- >> > You received this message because you are subscribed to the Google Groups "ossec-list" group. >> > To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. >> >> > For more options, visit https://groups.google.com/groups/opt_out. >> > >> > > > -- > > --- > You received this message because you are subscribed to the Google Groups "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. > For more options, visit https://groups.google.com/groups/opt_out. > > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
