On Mon, Oct 12, 2015 at 10:54 AM, James Edwards <[email protected]> wrote:
> Hi all,
>
> Is it possible to have OSSEC report the initial hash of the files indexed by
> the agent?
>
> As an example of the desired output:
>
> Oct 12 14:30:19 xxx.xx.x.xx Oct 12 10:29:29 ossec01 ossec: Alert Level: 7;
> Rule: 554 - File added to the system.; Location:
> (agent02.domain.example.com) xxx.xx.xx.xx ->syscheck; New file
> 'C:\monitored\path/file.name' added to the file system.  Current MD5:
> '019a716fbc346088d8c666e4eaa3e664'
>
> Is something like this even possible, or is there another way to get this
> information?
>

If it isn't done already, you would have to add it to the code.

> Thanks,
> James
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to