Thanks, but is there a more reasonable way to do it on 1 package and then deploy it ? and if so...how ? (I tried compiling an RPM and set "n" for root check on /ossec-hids-2.8.1/etc/preloaded-vars.conf but it doesn't work).
# If USER_ENABLE_ROOTCHECK is set to "y", # rootcheck will be enabled. Set to "n" to # disable it. USER_ENABLE_ROOTCHECK="n" On Tue, Jan 13, 2015 at 4:50 AM, dan (ddp) <[email protected]> wrote: > On Tue, Jan 13, 2015 at 7:44 AM, Yaniv Ron <[email protected]> wrote: > > Hi All, > > > > I would like to disable the agents from running the command netstat , how > > can I do it ? > > (I tried reading the document on OSSEC site but unfortunately I couldn't > > find anything) > > Remove the appropriate <localfile> entry in the agent's ossec.conf. > > > -- > > Yaniv Ron > > +972-3-7298582 > > Security Department | Viber S.a.r.l | www.viber.com | [email protected] > > > > -- > > > > --- > > You received this message because you are subscribed to the Google Groups > > "ossec-list" group. > > To unsubscribe from this group and stop receiving emails from it, send an > > email to [email protected]. > > For more options, visit https://groups.google.com/d/optout. > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. > -- *Yaniv Ron* +972-3-7298582 *Security Department | Viber S.a.r.l *| www.viber.com | yron@viber <http://twitter.com/viber>.com -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
