Dan now that you mention it I am not 100% sure about this. AI think it is
but haven't had time to fully test it.

On Tue, Mar 22, 2016 at 4:03 AM, dan (ddp) <[email protected]> wrote:

> On Mon, Mar 21, 2016 at 8:08 PM, Santiago Bassett
> <[email protected]> wrote:
> > Some questions that might help:
> >
> > - did you restart the agent after changing the configuration? (required,
> > unless it is pushed from the manager using shared agent.conf file)
> >
>
> A restart is required then too.
>
> > - did you specify the frequency of the checks? Most cases alerts are not
> > generated in real time. Even when using realtime option, it might take a
> few
> > minutes (could be about 5-10 minutes) to get the alert (this happens when
> > rootcheck is running)
> >
> > - did you get the file hashes listed in syscheck database (see
> > /var/ossec/queue/sysechck directory)?
> >
> > - did you configure the manager to alert for new files? (and also the
> rule)
> >
> > - did you set auto_ignore option to no? (in case the file has been
> modified
> > more than three times)
> >
> > Also I would recommend to use scan_on start option in the agent.
> >
> > I hope that helps,
> >
> > Santiago.
> >
> > On Wed, Mar 16, 2016 at 2:02 PM, thak <[email protected]> wrote:
> >>
> >> Hi,
> >>
> >> We added /var/application directories to our application servers'
> >> ossec.conf file, but we just rolled an application update (introducing
> new
> >> files and absolutely modifying older ones) and didn't get any updates.
> >>
> >> Any ideas on a likely issue here? Do we need to run the command to clear
> >> the syscheck file integrity database? Is there some requirement that
> OSSEC
> >> "rebaseline" the integrity hashes, such that they pick up this new
> rule's
> >> target directories?
> >>
> >> --
> >>
> >> ---
> >> You received this message because you are subscribed to the Google
> Groups
> >> "ossec-list" group.
> >> To unsubscribe from this group and stop receiving emails from it, send
> an
> >> email to [email protected].
> >> For more options, visit https://groups.google.com/d/optout.
> >
> >
> > --
> >
> > ---
> > You received this message because you are subscribed to the Google Groups
> > "ossec-list" group.
> > To unsubscribe from this group and stop receiving emails from it, send an
> > email to [email protected].
> > For more options, visit https://groups.google.com/d/optout.
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to