OSSEC-2.8.3 on Ubuntu 16.04

One OSSEC server with multiple agents.

/var/ossec/etc/ossec.conf on an agent:


/var/ossec/etc/shared/agent.conf on the server (and it's matched 
by /var/ossec/etc/shared/agent.conf on all agents):

<agent_config os="linux">
  <!-- Directories to check (perform all possible verifications) -->
  <directories check_all="yes">/etc,/usr/bin,/usr/sbin</directories>
  <directories check_all="yes">/bin,/sbin</directories>
    <!-- files we don't watch/ignore -->

  <!-- Files to monitor (localfiles) -->



So /etc/init.d/our-api is in the ignore list, I added it there earlier 
today. However, I just got an alert from multiple agents, after that file 
had changed after a deploy:

OSSEC HIDS Notification.
2016 Nov 23 21:25:49

Received From: (api-p1-front-012) any->syscheck
Rule: 552 fired (level 7) -> "Integrity checksum changed again (3rd time)."
Portion of the log(s):

Integrity checksum changed for: '/etc/init.d/our-api'

What is going on? It looks like adding a file to the ignore list does not 
exempt it from being flagged by the rules. If so, how do I truly ignore a 
given file everywhere?


You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to