On 2014-09-19 4:21, Chard wrote:
Hi,
I'm looking into Centralized agent configuration with OSSEC.
I understand that you create the file var/ossec/etc/shared/agent.conf.
But does this need to include all the default config of ossec as well
as any additional option I may add? eg include this.
If you are going to use agent.conf, I recommend keeping the ossec.conf
as bare-bones as possible. On 'nix, all you need in there is to tell it
where the server is. On Windows, you need that, along with a specific
declaration to enable active response if you want the capability to
restart the agent remotely. You'll want that capability because
whenerver you change agent.conf, a restart of the agent is necessary to
read the new config. Using this approach, you can easily see what
configuration all agents have simply by looking on the manager.
--
---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.