On 2014-09-19 4:21, Chard wrote:
Hi,

I'm looking into Centralized agent configuration with OSSEC.

I understand that you create the file var/ossec/etc/shared/agent.conf.


But does this need to include all the default config of ossec as well
as any additional option I may add? eg include this.

If you are going to use agent.conf, I recommend keeping the ossec.conf as bare-bones as possible. On 'nix, all you need in there is to tell it where the server is. On Windows, you need that, along with a specific declaration to enable active response if you want the capability to restart the agent remotely. You'll want that capability because whenerver you change agent.conf, a restart of the agent is necessary to read the new config. Using this approach, you can easily see what configuration all agents have simply by looking on the manager.

--

--- You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to