Hello,

Thanks for the reply, but I can not get it to work.

I made changes to the file as you indicate and I tried to restart ossec but 
it failed.

root@OSSEC-SERVER-UBUNTU:/var/ossec/etc# cat ossec.conf | grep rules
  <rules>
    <include>rules_config.xml</include>
    <include>ossec_rules.xml</include>
    <include>local_rules.xml</include>
  </rules>
root@OSSEC-SERVER-UBUNTU:/var/ossec/etc# ../bin/ossec-control restart
ossec-monitord not running ..
ossec-logcollector not running ..
ossec-remoted not running ..
ossec-syscheckd not running ..
ossec-analysisd not running ..
ossec-maild not running ..
ossec-execd not running ..
ossec-dbd not running ..
OSSEC HIDS v2.8.3 Stopped
Starting OSSEC HIDS v2.8.3 (by Trend Micro Inc.)...
OSSEC analysisd: Testing rules failed. Configuration error. Exiting.
root@OSSEC-SERVER-UBUNTU:/var/ossec/etc#

El miércoles, 26 de abril de 2017, 16:26:02 (UTC+2), Nikki S escribió:
>
> Yes, you can disable all rules via OSSEC.conf. From the testing I did, the 
> only rules that have to always remain enabled are OSSEC.rules, rules_config 
> and local rules
>
> On Tuesday, April 25, 2017 at 11:25:57 AM UTC-4, Huc Manté Miras wrote:
>>
>> Hello,
>>
>> I try to disable all rules to ossec server.
>>
>> This is possible?
>>
>> Thanks!!
>>
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to