Hello community, I am using OSSEC for monitoring of my Linux and Windows based servers and it is working flawlessly. Initially the number of servers I was managing through OSSEC were less so individual configuration was easy. Now I want to shift to the centralized agent configuration. I followed the instructions in the documentation and I am able to configure the agents remotely based upon their name. However, I have a little confusion. When we create /var/ossec/etc/shared/agent.conf file and push it to the agents, does it mean that the /var/ossec/etc/ossec.conf (or ossec-agent.conf because both are the same) will be ignored? The agent has now one configuration file in /var/ossec/etc/shared/agent.conf that was pushed from the manager and one conf file in the /var/ossec/etc/ directory that it was using previously.
A little clarification will be very helpful. Thanks a lot for your support and for such a wonderful product. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
