Hello, Thanks for the reply, but I can not get it to work.
I made changes to the file as you indicate and I tried to restart ossec but it failed. root@OSSEC-SERVER-UBUNTU:/var/ossec/etc# cat ossec.conf | grep rules <rules> <include>rules_config.xml</include> <include>ossec_rules.xml</include> <include>local_rules.xml</include> </rules> root@OSSEC-SERVER-UBUNTU:/var/ossec/etc# ../bin/ossec-control restart ossec-monitord not running .. ossec-logcollector not running .. ossec-remoted not running .. ossec-syscheckd not running .. ossec-analysisd not running .. ossec-maild not running .. ossec-execd not running .. ossec-dbd not running .. OSSEC HIDS v2.8.3 Stopped Starting OSSEC HIDS v2.8.3 (by Trend Micro Inc.)... OSSEC analysisd: Testing rules failed. Configuration error. Exiting. root@OSSEC-SERVER-UBUNTU:/var/ossec/etc# El miércoles, 26 de abril de 2017, 16:26:02 (UTC+2), Nikki S escribió: > > Yes, you can disable all rules via OSSEC.conf. From the testing I did, the > only rules that have to always remain enabled are OSSEC.rules, rules_config > and local rules > > On Tuesday, April 25, 2017 at 11:25:57 AM UTC-4, Huc Manté Miras wrote: >> >> Hello, >> >> I try to disable all rules to ossec server. >> >> This is possible? >> >> Thanks!! >> > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.