Dear Dan,
Ok I think you are referring to this right.
<!-- Files to monitor (localfiles) --> . So in my scenario which .conf to
look into the one ossec.conf or ossec-server.conf?
On Wed, Sep 11, 2013 at 2:40 AM, dan (ddp) <[email protected]> wrote:
> On Tue, Sep 10, 2013 at 2:34 PM, frwa onto <[email protected]> wrote:
> > Dear Dan,
> > My question is why the entry list of
> > /var/ossec/queue/syscheck/syscheck is so little. I am sure the total
> files I
> > have in my system is more then this list am I right?
> >
>
> I don't know. Check the directories you have configured in the
> ossec.conf (<directories> entries in the <syscheck> section). Those
> are the directories containing the files listed in that db file. If
> you want something monitored, the directory must be defined in the
> ossec.conf.
>
> --
>
> ---
> You received this message because you are subscribed to a topic in the
> Google Groups "ossec-list" group.
> To unsubscribe from this topic, visit
> https://groups.google.com/d/topic/ossec-list/n0-gBzCdh3M/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to
> [email protected].
> For more options, visit https://groups.google.com/groups/opt_out.
>
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.