Re: [ossec-list] Re: OSSEC: Real time file monitoring not starting

2018-02-23 Thread temp . email . ith
So what is the difference, between say, the parameter in the ossec.conf file on the Server and the agent.conf file that eventually gets uploaded to the Agent? I was under the impression that the frequency setting in ossec.conf would be used locally if the Server were performing syschecks on

Re: [ossec-list] Re: OSSEC: Real time file monitoring not starting

2018-02-23 Thread Santiago Bassett
That goes on the manager ossec.conf The manager takes care of analyzing syscheck data received from the agents, and generate alerts. I hope it helps Santiago Bassett @santiagobassett > On Feb 23, 2018, at 9:59 AM, temp.email@gmail.com wrote: > > Hi Santiago, I just came across your post.

Re: [ossec-list] Re: OSSEC: Real time file monitoring not starting

2018-02-23 Thread temp . email . ith
Hi Santiago, I just came across your post. Are you saying that the auto_ignore and alert_new_files goes in /var/ossec/etc/ossec.conf on the manager OR in /var/ossec/etc/shared/agent.conf on the manager? Obviously, the latter will eventually be placed on the Agent. I thought that

Re: [ossec-list] Re: OSSEC: Real time file monitoring not starting

2015-11-12 Thread Santiago Bassett
Are you using scan_on_start option? Remember realtime won't work until first syscheck is done. I also recommend to use alert_new_files and set auto_ignore to "no" (this goes on the manager). Useful trobleshooting tip is to enable debug for syscheck on the agent (internal_options.conf file) Best