Is it expensive to restart an agent? For my case (the OP) I can use consul-template to watch for the when the ossec-remoted's IP has changed and rewrite the IP in the config file then restart the agent. Would the reconnects to the server need to spread out or can it handle the thundering herd of reconnects?
As for AWS not giving stable IPs: This really makes no sense when using auto-scaling-groups inside a private CIDR address space. If three nodes are scaled down and later five more a scaled up which would get what IPs? (This is not my original use-case though. The ossec-server is a "well known" and stable instance.) -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
