On 04/05/2014 06:07 AM, BP9906 wrote:
The only tricky part is restarting the agent after agent.conf get pulled down
which couls be a while.
You can use ossec to detect the new/changed agent.conf and then fire the
restart-ossec.sh active response. You just have to make sure that it's a
good active response so you don't end up with an entire infrastructure
of inactive agents due to ossec refusing to start.
--
---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.