On Mon, Mar 31, 2014 at 6:46 PM, Razvan Oncioiu <[email protected]> wrote: > Hello All, > > I know this has been discussed before, but it seems to still be an issue. On > the client servers that have nfs mount ( we have a few with mounts in > /var/www ) , when ever I start the ossec client the load goes up quite a > bit. I have set both <ignore>/var/www</ignore> and ignore type regex to no > avail. I would get an error when I tried to add > <check_policy>no</check_policy> under rootcheck. It seems the only thing I > can do to alleviate this situation is to turn off rootcheck all together, > and I would rather have parts of it on. > > I'm a bit stuck here and I'm not sure what to do, can someone help me? >
I might be misunderstanding the problem, but you can customize the rootcheck checks. Those rootcheck "check files" (what do we call them?) are editable, or you can create your own files. > Thank You. > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
