Thank you for the suggestions! We definitely have the /var/application hashes in the manager's /var/ossec/queue/syscheck files.
So it's definitely picking them up, just does not seem to be alerting or emailing. On my test instance I also cannot seem to get realtime alerting working. I know I enabled it during installation, I think, but it does not seem to detect in realtime (despite inotify-tools being installed). On Monday, March 21, 2016 at 8:09:01 PM UTC-4, Santiago Bassett wrote: > > Some questions that might help: > > - did you restart the agent after changing the configuration? (required, > unless it is pushed from the manager using shared agent.conf file) > > - did you specify the frequency of the checks? Most cases alerts are not > generated in real time. Even when using realtime option, it might take a > few minutes (could be about 5-10 minutes) to get the alert (this happens > when rootcheck is running) > > - did you get the file hashes listed in syscheck database (see > /var/ossec/queue/sysechck directory)? > > - did you configure the manager to alert for new files? (and also the rule) > > - did you set auto_ignore option to no? (in case the file has been > modified more than three times) > > Also I would recommend to use scan_on start option in the agent. > > I hope that helps, > > Santiago. > > On Wed, Mar 16, 2016 at 2:02 PM, thak <[email protected] <javascript:>> > wrote: > >> Hi, >> >> We added /var/application directories to our application servers' >> ossec.conf file, but we just rolled an application update (introducing new >> files and absolutely modifying older ones) and didn't get any updates. >> >> Any ideas on a likely issue here? Do we need to run the command to clear >> the syscheck file integrity database? Is there some requirement that OSSEC >> "rebaseline" the integrity hashes, such that they pick up this new rule's >> target directories? >> >> -- >> >> --- >> You received this message because you are subscribed to the Google Groups >> "ossec-list" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to [email protected] <javascript:>. >> For more options, visit https://groups.google.com/d/optout. >> > > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
