Yes, what Dan says make sense. In addition you can use "logall" option, so not only alerts are logged, but also every log message. The output goes to /var/ossec/logs/archives/archives.log
If what you need is to show them in ossec.log at the monitored host, you can enable agent debug at internal_options.conf On Fri, Dec 4, 2015 at 5:15 AM, dan (ddp) <[email protected]> wrote: > On Fri, Dec 4, 2015 at 2:45 AM, 林威任 <[email protected]> wrote: > > I hacked my ossec-agent to get the logs, > > but the logs do not appear the ossec.log. > > Therefore,I want to ask why it does not show up. > > Thank you!!! > > > > Logs appear in the /var/ossec/logs/alerts/alerts.log file on the OSSEC > server (or locally for a local installation). > Without more information (like the logs created by the apps you > hacked), it's tough to help much more. > > > -- > > > > --- > > You received this message because you are subscribed to the Google Groups > > "ossec-list" group. > > To unsubscribe from this group and stop receiving emails from it, send an > > email to [email protected]. > > For more options, visit https://groups.google.com/d/optout. > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
