On Mon, Oct 12, 2015 at 10:54 AM, James Edwards <[email protected]> wrote: > Hi all, > > Is it possible to have OSSEC report the initial hash of the files indexed by > the agent? > > As an example of the desired output: > > Oct 12 14:30:19 xxx.xx.x.xx Oct 12 10:29:29 ossec01 ossec: Alert Level: 7; > Rule: 554 - File added to the system.; Location: > (agent02.domain.example.com) xxx.xx.xx.xx ->syscheck; New file > 'C:\monitored\path/file.name' added to the file system. Current MD5: > '019a716fbc346088d8c666e4eaa3e664' > > Is something like this even possible, or is there another way to get this > information? >
If it isn't done already, you would have to add it to the code. > Thanks, > James > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
