On Tue, Jan 13, 2015 at 9:40 AM, Martin Kvocka <mkvo...@gmail.com> wrote: > Hi, > > we have Ossec server/agents (2.7.0) for monitoring file integrity. Both > include check_all="yes" in their syscheck configurations. The agents work > perfectly and report file changes including their old/current MD5 and SHA1 > hashes. However, logs from the Ossec server machine report only file > changes, but don't include the hashes. > > Did any of you encounter this issue? How should I debug it? >
Can you show us an example? Do the hashes exist in the syscheck db for the manager? > Thanks > > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to ossec-list+unsubscr...@googlegroups.com. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. For more options, visit https://groups.google.com/d/optout.