I am running OSSEC with monitoring set on /etc with syscheck running every
30 minutes.
I will make a change to a file and I receive an alert that the file has
changed the next time syscheck runs.
I then change the fill back to its original state, but I do not receive an
alert that the file has been changed.
If I make a different change to the file, I receive an alert. It's ONLY
when the file changes back to it's original state that I do not receive an
alert.
Is this a configuration issue that I am missing?
Please let me know if this makes sense.
Thanks!
Below is the ossec.conf file on the agent:
<!-- OSSEC example config -->
<ossec_config>
<client>
<server-ip>10.0.1.10</server-ip>
</client>
<syscheck>
<!-- Frequency that syscheck is executed -->
<frequency>1800</frequency>
<alert_new_files>yes</alert_new_files>
<!-- Directories to check (perform all possible verifications) -->
<directories report_changes="yes" check_all="yes">/etc</directories>
<directories report_changes="yes" realtime="yes"
check_all="yes">/bin,/sbin,/usr/bin,/usr/sbin,/usr/local/bin,/usr/local/sbin</directories>
<!-- Files/directories to ignore -->
<ignore>/etc/mtab</ignore>
<ignore>/etc/hosts.deny</ignore>
<ignore>/etc/mail/statistics</ignore>
<ignore>/etc/random-seed</ignore>
<ignore>/etc/adjtime</ignore>
<ignore>/etc/httpd/logs</ignore>
<ignore>/etc/lvm/archive</ignore>
<ignore>/etc/lvm/backup</ignore>
<ignore>/etc/lvm/cache</ignore>
<ignore>/etc/service/</ignore>
</syscheck>
<rootcheck>
<rootkit_files>/var/ossec/etc/shared/rootkit_files.txt</rootkit_files>
<rootkit_trojans>/var/ossec/etc/shared/rootkit_trojans.txt</rootkit_trojans>
</rootcheck>
<localfile>
<log_format>full_command</log_format>
<command>netstat -tan |grep LISTEN |grep -v 127.0.0.1 | sort</command>
</localfile>
</ossec_config>
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.