Yes, needed to do this otherwise the folder wouldn't work (if i remember correct) I've another problem at the moment with the realtime monitoring not working.
On Tuesday, 24 April 2018 00:32:21 UTC+2, dan (ddpbsd) wrote: > > On Fri, Apr 20, 2018 at 10:25 AM, Patrik Lindh <[email protected] > <javascript:>> wrote: > > Hello! > > I've installed Ossec windoiws agent on a server 2008r2 and want to > monitor > > logs residing in:C:\ProgramData\GlobalSCAPE\EFT Server Enterprise/Logs > > > > But when i start the agent i get the following error: 2018/04/20 > 14:54:42 > > ossec-logcollector(1103): ERROR: Could not open file > > 'C:\ProgramData\GlobalSCAPE\EFT Server Enterprise/Logs' due to [(9)-(Bad > > file descriptor)]. > > > > Possibly unrelated, but your slashes are odd. You use backslashes > until you get to Logs, then you use a forward slash. > > > Any idea why? > > > > The folder contains about 150 logs (5 new a day and kept in 30days) > > > > What I want to accomplish is to monitor the logs so that nobody changes > them > > and if someone do I want OSSEC to report it. > > > > > > //P > > > > -- > > > > --- > > You received this message because you are subscribed to the Google > Groups > > "ossec-list" group. > > To unsubscribe from this group and stop receiving emails from it, send > an > > email to [email protected] <javascript:>. > > For more options, visit https://groups.google.com/d/optout. > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
