On Mon, Aug 12, 2013 at 11:24 AM, vtrack <[email protected]> wrote: > Hi, > > Does OSSEC configuration file (/var/ossec/etc/ossec.conf) on every clients > (where ossec agent running) require same rules as mentioned in the OSSEC
Agents do not analyse log messages, the servers handle this. Only the servers have rules. > server? For example, I have an SMTP server and few new file rules mentioned > in the server conf file, however I do not have the same in agent side. I > would need to monitor client systems for any file changes and alert via > smtp. > > Is that case, do I need to update client conf file as well? > > Thanks much. > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/groups/opt_out. > > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
