On Thu, Feb 23, 2017 at 9:30 AM, InfoSec <[email protected]> wrote: > I tend to think that the Windows Agent is the culprit. > > Can the agent be temporarily run in debug mode, so it logs locally the > events that it forwards to the server? >
There are no options for that. The best you can do is turn the logall option on the server on, and see what it receives from the agents. > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
