On 04/05/2014 06:07 AM, BP9906 wrote:
The only tricky part is restarting the agent after agent.conf get pulled down 
which couls be a while.

You can use ossec to detect the new/changed agent.conf and then fire the restart-ossec.sh active response. You just have to make sure that it's a good active response so you don't end up with an entire infrastructure of inactive agents due to ossec refusing to start.


--

--- You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to