[ossec-list] ssmtp, gmail and smtp server

2019-09-20 Thread llehirgen
I installed ssmtp on Ubuntu and configured it to use smtp.gmail.com on port 
587 as mail server.
My intention is to send all local emails (OSSEC, rkhunter and fail2ban) to 
a gmail account.
What am I expect to write during installation when asked about SMTP server?
What value do I have to use for the 'smtp_server' directive in ossec.conf?

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/384ebb57-52ef-421d-a12d-390004df3398%40googlegroups.com.


[ossec-list] ssmtp, gmail and smtp server

2019-09-20 Thread llehirgen
I installed ssmtp on Ubuntu and configured it to use smtp.gmail.com on port 
587 as mail server.
My intention is to send all local emails (OSSEC, rkhunter and fail2ban) to 
a gmail account.
What am I expect to write during installation when asked about SMTP server?
What value do I have to use for the 'smtp_server' directive in ossec.conf?

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/e99b6f9f-00a3-4cc5-a94d-e20343405e3c%40googlegroups.com.


[ossec-list] ssmtp, gmail and smtp server

2019-09-20 Thread llehirgen
I installed ssmtp on Ubuntu and configured it to use smtp.gmail.com on port 
587 as mail server.
My intention is to send all local emails (OSSEC, rkhunter and fail2ban) to 
a gmail account.
What am I expect to write during installation when asked about SMTP server?
What value do I have to use for the 'smtp_server' directive in ossec.conf?

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/f9d7aba4-7fbb-4783-9972-e281748a3145%40googlegroups.com.


[ossec-list] ssmtp, gmail and smtp server

2019-09-20 Thread llehirgen
I installed ssmtp on Ubuntu and configured it to use smtp.gmail.com on port 
587 as mail server.
My intention is to send all local emails (OSSEC, rkhunter and fail2ban) to 
a gmail account.
What am I expect to write during installation when asked about SMTP server?
What value do I have to use for the 'smtp_server' directive in ossec.conf?

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/7994af0b-e01e-40da-aacb-7f68a9cf10de%40googlegroups.com.


[ossec-list] ssmtp, gmail and smtp server

2019-09-20 Thread llehirgen
I installed ssmtp on Ubuntu and configured it to use smtp.gmail.com on port 
587 as mail server.
My intention is to send all local emails (OSSEC, rkhunter and fail2ban) to 
a gmail account.
What am I expect to write during installation when asked about SMTP server?
What value do I have to use for the 'smtp_server' directive in ossec.conf?

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/3bb9fe7f-0a70-4c90-a3db-484c23c131ed%40googlegroups.com.


[ossec-list] ssmtp, gmail and smtp server

2019-09-20 Thread llehirgen
I installed ssmtp on Ubuntu and configured it to use smtp.gmail.com on port 
587 as mail server.
My intention is to send all local emails (OSSEC, rkhunter and fail2ban) to 
a gmail account.
What am I expect to write during installation when asked about SMTP server?
What value do I have to use for the 'smtp_server' directive in ossec.conf?

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/1d26ef74-afbe-4af2-9b90-36724101c3d6%40googlegroups.com.


[ossec-list] ssmtp, gmail and smtp server

2019-09-20 Thread llehirgen
I installed ssmtp on Ubuntu and configured it to use smtp.gmail.com on port 
587 as mail server.
My intention is to send all local emails (OSSEC, rkhunter and fail2ban) to 
a gmail account.
What am I expect to write during installation when asked about SMTP server?
What value do I have to use for the 'smtp_server' directive in ossec.conf?

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/5cd14b51-227d-4707-82d9-c842622b5c6b%40googlegroups.com.


Re: [ossec-list] ossec-dbd ERROR: Error executing query 'Insert into alert....'

2019-09-20 Thread dan (ddp)
On Thu, Sep 19, 2019 at 3:24 PM Jerry Lowry  wrote:
>
> Dan,
> Just check the server log again and found this error from the dbd process:
> 2019/09/19 04:07:04 ossec-dbd(5203): ERROR: Error executing query 'INSERT 
> INTO 
> alert(server_id,rule_id,level,timestamp,location_id,src_ip,src_port,dst_ip,dst_port,alertid,user,full_log,tld)
>  VALUES ('1', '1002','2','1568891224', '1', '(null)', '0', '(null)', '0', 
> '1568891220.0', '(null)', 'Sep 19 04:06:59 obed audispd: node=obed.edt.com 
> type=ANOM_RBAC_INTEGRITY_FAIL msg=audit(1568891219.881:80020): pid=6481 uid=0 
> auid=0 ses=1145 msg=`added=39777 removed=272 changed=2021 
> exe="/usr/sbin/aide" hostname=? addr=? terminal=? res=failed`','')'. Error: 
> 'MySQL server has gone away'.
> 2019/09/19 04:07:04 ossec-dbd(5209): INFO: Closing connection to database.
> 2019/09/19 04:07:04 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:07:04 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).

I wouldn't trust localhost for this. I think ossec-dbd chroot()s to
/var/ossec, but can't remember for sure.
Did you copy /etc/hosts to /var/ossec/etc/hosts? That might be enough
to make sure dns resolution works.


> 2019/09/19 04:07:06 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:07:06 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:07:10 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:07:10 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:07:11 INFO: Connected to 10.20.10.6 at address 10.20.10.6, port 
> 25
> 2019/09/19 04:07:12 os_sendmail(1764): WARN: Mail from not accepted by server

So the default mail from email address (os...@example.com I think)
isn't allowed by your smtp server.
You can change this value with the  option in the 
section of the server's ossec.conf.

> 2019/09/19 04:07:12 ossec-maild(1223): ERROR: Error Sending email to 
> 10.20.10.6 (smtp server)
> 2019/09/19 04:07:18 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:07:18 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:07:34 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:07:34 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:08:06 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:08:06 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:09:10 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:09:10 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:11:18 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:11:18 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:15:34 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:15:34 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:24:06 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:24:06 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 04:41:10 ossec-dbd(5210): INFO: Attempting to reconnect to 
> database.
> 2019/09/19 04:41:10 ossec-dbd(5202): ERROR: Error connecting to database 
> 'localhost'(ossec): ERROR: Unknown MySQL server host 'localhost' (-11).
> 2019/09/19 05:02:14 INFO: Connected to 10.20.10.6 at address 10.20.10.6, port 
> 25
> 2019/09/19 05:02:15 os_sendmail(1764): WARN: Mail from not accepted by server
> 2019/09/19 05:02:15 ossec-maild(1223): ERROR: Error Sending email to 
> 10.20.10.6 (smtp server)
> 2019/09/19 05:15:18 ossec-dbd(5208): ERROR: Multiple database errors. Exiting.
> 2019/09/19 11:43:07 INFO: Connected to 10.20.10.6 at address 10.20.10.6, port 
> 25
> 2019/09/19 11:43:07 os_sendmail(1764): WARN: Mail from not accepted by server
> 2019/09/19 11:43:07 ossec-maild(1223): ERROR: Error Sending email to 
> 10.20.10.6 (smtp server)
>
> So I just listed all the log from the database error on.  There are no errors 
> above this that point to the database going away.  The log is clean other 
> than the email error ( which is baffling). Not sure what it missing on this.
> Do you have any ideas as to why the database server would just go 

Re: [ossec-list] ossec-dbd ERROR: Error executing query 'Insert into alert....'

2019-09-20 Thread dan (ddp)
On Thu, Sep 19, 2019 at 3:12 PM Jerry Lowry  wrote:
>
> No, actually it is not in the mysql schema that is downloaded in the tar.  I 
> inserted it based on what you showed me in the postgres schema.

>From the mysql.schema file in the 3.3.0.tar.gz downloaded from github
on July 26, 2019:
CREATE TABLE IF NOT EXISTS  alert
(
id  INT UNSIGNED NOT NULL  AUTO_INCREMENT,
server_id   SMALLINTUNSIGNED NOT NULL,
rule_id MEDIUMINT   UNSIGNED NOT NULL,
level   TINYINT UNSIGNED,

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/CAMyQvMoHvgTjiT9m2V%3DcyuwY0TiNC2g95AzKP58spxgZY-3W%2Bw%40mail.gmail.com.


Re: [ossec-list] Help with using Ossec's Syscheck

2019-09-20 Thread dan (ddp)
On Thu, Sep 19, 2019 at 9:38 AM Paul Rogers  wrote:
>
>
>
> On Wednesday, September 18, 2019 at 11:45:07 AM UTC-4, dan (ddpbsd) wrote:
>>
>> On Wed, Sep 18, 2019 at 11:09 AM Paul Rogers  wrote:
>> >
>> > I ran the command you gave ( /var/ossec/bin/ossec-syscheckd -d) and got 
>> > this:
>> > 2019/09/18 15:06:22 ossec-syscheckd: DEBUG: Starting ...
>> > 2019/09/18 15:06:22 ossec-syscheckd(1756): ERROR: Duplicated directory 
>> > given: '/  
>> >home'.
>> > 2019/09/18 15:06:22 ossec-syscheckd(1756): ERROR: Duplicated directory 
>> > given: '/  
>> >etc'.
>> > 2019/09/18 15:06:22 ossec-syscheckd(1756): ERROR: Duplicated directory 
>> > given: '/  
>> >sbin'.
>> > 2019/09/18 15:06:22 rootcheck: DEBUG: Starting ...
>> > 2019/09/18 15:06:22 rootcheck: Starting queue ...
>> > 2019/09/18 15:06:22 ossec-syscheckd: INFO: (unix_domain) Maximum send 
>> > buffer set 
>> >  to: '212992'.
>> >
>>
> How would i enable this for better results?
>

If you mean the added debugging I mentioned, I think you just
recompile with the DEBUG flag enabled.
DEBUG=yes ./install.sh

The duplicated directories seem to be in both the ossec.conf and
agent.conf. I'm not sure which one takes priority.
It might be worth modifying the ossec.conf on an agent and testing the
changes there.

>
>>
>> It's possible I get more output because I compile with DEBUG enabled.
>>
>> > As for the restarting and making changes on the agents i did do that but 
>> > was also a bit confused as I've read that is you right it solely in the 
>> > server config file it would over right the agent config file forcefully.
>> >
>>
>
>
> I have this under the agent.conf in the shared directory. As for the 
> audit.log is that in the ossec files or the system files? I didn't locate  it 
> in the ossec files.

The system's audit.log. Usually in /var/log/audit I think.

> When i restart the agent i get something like this.
> calling os_read_agent_profile().
> 2019/09/19 13:33:16 ossec-syscheckd: os_read_agent_profile() = [-]
> 2019/09/19 13:33:16 rootcheck: DEBUG: Starting ...
> 2019/09/19 13:33:16 agent_config element does not have any attributes.
> 2019/09/19 13:33:16 ossec-syscheckd: calling os_read_agent_profile().
> 2019/09/19 13:33:16 ossec-syscheckd: os_read_agent_profile() = [-]
> 2019/09/19 13:33:16 rootcheck: Starting queue ...
>
> Sorry for so many questions the errors I've got seem to have very little 
> documentation for them.
>
>>
>> The agent.conf file gets pushed to the agents (which still requires a
>> restart), but the ossec.conf does not.
>> Based on your response and the errors above, I'm guessing this
>> configuration is from the agent.conf?
>> Another place to look for errors is in the audit.log file. Maybe the
>> copies are getting blocked by something else?
>>
>> > On Wednesday, September 18, 2019 at 10:43:13 AM UTC-4, dan (ddpbsd) wrote:
>> >>
>> >> On Wed, Sep 18, 2019 at 10:27 AM Paul Rogers  
>> >> wrote:
>> >> >
>> >> > Hello, I've been trying to use Ossec's syscheck as a FIM tool for a 
>> >> > while now. But I keep running into the problem of that it will only 
>> >> > report checksum changes on certain directories. Even with those 
>> >> > directories it won't report the changes that took place, like I've seen 
>> >> > over all the other documentation that I could find regarding it. Some 
>> >> > direction or understanding of what i could change or add would be 
>> >> > greatly appreciated. I've also noticed that there is no diff directory 
>> >> > or file on my ossec. Below is what my current configuration is for 
>> >> > ossec. I'm using this to monitor Ubuntu 18.04 servers.
>> >> >
>> >> >
>> >>
>> >> I don't use the "report_changes" option, so I don't know if it shows
>> >> up somewhere.
>> >> But you could run syscheckd in debug mode
>> >> (`/var/ossec/bin/ossec-syscheckd -d`) and look for lines like:
>> >> ossec-syscheckd: INFO: Monitoring directory: '/bin', with options perm
>> >> | size | owner | group | md5sum | sha256sum.
>> >>
>> >> That might mention report_changes in it. It might not.
>> >>
>> >> Did you restart the ossec agents after modifying the ossec.conf file?
>> >> Since  is present, I assume this is the ossec server's
>> >> ossec.conf. Did you also make the change on the agents?
>> >>
>> >> >
>> >> >
>> >> >  
>> >> >   
>> >> >   600
>> >> >   no
>> >> >   yes
>> >> >   /home,/etc,/bin/,/sbin,/usr
>> >> >
>> >> >   
>> >> >   yes
>> >> >
>> >> >   
>> >> >   > >> > report_changes="yes">/home
>> >> >   > >> > report_changes="yes">/etc
>> >> >   > >> > report_changes="yes">/usr/bin,/usr/sbin
>> 

Re: [ossec-list] Enable File Integrity

2019-09-20 Thread dan (ddp)
On Fri, Sep 20, 2019 at 4:42 AM Hardik Joshi  wrote:
>
> i want to enable email alert for file created,modified,deleted with example.
>

For syscheck, I think it's something like:
On the server:

  yes


On an agent:

  /path/to/directory


If you don't want to auto ignore files after 3 changes, disable the
auto_ignore option to the server.


...
no


Emailing syscheck alerts should already work out of the box (assuming
emailing alerts works).

> Thanks
> Hardik Joshi
> 853164
>
>
> On Wed, Sep 18, 2019 at 5:16 PM dan (ddp)  wrote:
>>
>> On Wed, Sep 11, 2019 at 7:21 AM Hardik Joshi  wrote:
>> >
>> > Hi,
>> >
>> > i want to windows file monitoring on every server, can you please help me 
>> > how to do this? with example please.
>> >
>>
>> syscheck is enabled by default on Windows systems.
>> What changes are you looking to make to the configuration?
>>
>> > Thanks
>> > Hardik Joshi
>> > 853164
>> >
>> >
>> > On Thu, Jul 11, 2019 at 4:35 PM dan (ddp)  wrote:
>> >>
>> >> On Thu, Jul 11, 2019 at 2:12 AM Hardik Joshi  wrote:
>> >> >
>> >> > Thanks for information.
>> >> >
>> >> >  I am unable to found  agent.conf  file in /var/ossec/etc/shared 
>> >> > folder. can you pls provide exact details how to create and configure.
>> >> >
>> >>
>> >> The documentation we currently have for this is pretty sparse.
>> >>
>> >> Use your favorite text editor to create the file on the OSSEC server.
>> >> In that file start with:
>> >>
>> >> 
>> >> 
>> >>
>> >> Between those 2 lines, enter your configuration.
>> >> For example, to add `/var/test` to the syscheck configuration of all
>> >> agents, use:
>> >>
>> >> 
>> >>   
>> >> /var/test
>> >>   
>> >> 
>> >>
>> >> Multiple "" blocks can be included in a single agent.conf.
>> >> When the agent.conf is modified, the agent's ossec processes will have
>> >> to be restarted for it to take effect.
>> >>
>> >> To limit which agents the configuration applies to, you can add
>> >> modifiers to the agent_config line.
>> >> There is "os," "name," and "profile" available.
>> >>
>> >> "os" defines the operating system of the agents the configuration will
>> >> apply on. For example you can use "Windows" or "Linux":
>> >> 
>> >>
>> >> "name" is the name of an agent. If you want the configuration block to
>> >> apply to a specific agent, use this option.
>> >> 
>> >>
>> >> "profile" is a descriptive term that you can use to group agents. The
>> >> agent "subscribes" to the profile in its ossec.conf.
>> >> I haven't used this option in years, so I don't remember how to use it 
>> >> off hand.
>> >>
>> >>
>> >> > Thanks
>> >> > Hardik Joshi
>> >> >
>> >> >
>> >>
>> >> Hope this helps. Feel free to watch this space for further updates:
>> >> https://ossec-documentation.readthedocs.io/en/latest/configuration/agent_conf.html
>> >>
>> >> --
>> >>
>> >> ---
>> >> You received this message because you are subscribed to the Google Groups 
>> >> "ossec-list" group.
>> >> To unsubscribe from this group and stop receiving emails from it, send an 
>> >> email to ossec-list+unsubscr...@googlegroups.com.
>> >> To view this discussion on the web visit 
>> >> https://groups.google.com/d/msgid/ossec-list/CAMyQvMpvgO9ts1LDQMBNAMYZDM4vbfCxzXcc%2BvaCyeADfP_HoQ%40mail.gmail.com.
>> >> For more options, visit https://groups.google.com/d/optout.
>> >
>> > --
>> >
>> > ---
>> > You received this message because you are subscribed to the Google Groups 
>> > "ossec-list" group.
>> > To unsubscribe from this group and stop receiving emails from it, send an 
>> > email to ossec-list+unsubscr...@googlegroups.com.
>> > To view this discussion on the web visit 
>> > https://groups.google.com/d/msgid/ossec-list/CAFjM2gNzHK7q7T%2Btwmp45DQrbAh01fUVhLX_V5ecuBg1ViVWWg%40mail.gmail.com.
>>
>> --
>>
>> ---
>> You received this message because you are subscribed to the Google Groups 
>> "ossec-list" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email to ossec-list+unsubscr...@googlegroups.com.
>> To view this discussion on the web visit 
>> https://groups.google.com/d/msgid/ossec-list/CAMyQvMot6a7tN0VjWTm2A%3DLYWA2mAO0z5GeT0CN7N7AC1Gn1XA%40mail.gmail.com.
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups 
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to ossec-list+unsubscr...@googlegroups.com.
> To view this discussion on the web visit 
> https://groups.google.com/d/msgid/ossec-list/CAFjM2gMYxChx4%3DNBe3Wh0_bW0t2yMqsa5AatTQMep%3D8BPMuF3w%40mail.gmail.com.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/CAMyQvMrNNJvxj-d14FLOwjqCJwAbxnTEfCHYzmLPgqqnOXEdkQ%40mail.gmail.com.


Re: [ossec-list] Enable File Integrity

2019-09-20 Thread Hardik Joshi
i want to enable email alert for file created,modified,deleted with example.

Thanks
Hardik Joshi
853164


On Wed, Sep 18, 2019 at 5:16 PM dan (ddp)  wrote:

> On Wed, Sep 11, 2019 at 7:21 AM Hardik Joshi  wrote:
> >
> > Hi,
> >
> > i want to windows file monitoring on every server, can you please help
> me how to do this? with example please.
> >
>
> syscheck is enabled by default on Windows systems.
> What changes are you looking to make to the configuration?
>
> > Thanks
> > Hardik Joshi
> > 853164
> >
> >
> > On Thu, Jul 11, 2019 at 4:35 PM dan (ddp)  wrote:
> >>
> >> On Thu, Jul 11, 2019 at 2:12 AM Hardik Joshi 
> wrote:
> >> >
> >> > Thanks for information.
> >> >
> >> >  I am unable to found  agent.conf  file in /var/ossec/etc/shared
> folder. can you pls provide exact details how to create and configure.
> >> >
> >>
> >> The documentation we currently have for this is pretty sparse.
> >>
> >> Use your favorite text editor to create the file on the OSSEC server.
> >> In that file start with:
> >>
> >> 
> >> 
> >>
> >> Between those 2 lines, enter your configuration.
> >> For example, to add `/var/test` to the syscheck configuration of all
> >> agents, use:
> >>
> >> 
> >>   
> >> /var/test
> >>   
> >> 
> >>
> >> Multiple "" blocks can be included in a single agent.conf.
> >> When the agent.conf is modified, the agent's ossec processes will have
> >> to be restarted for it to take effect.
> >>
> >> To limit which agents the configuration applies to, you can add
> >> modifiers to the agent_config line.
> >> There is "os," "name," and "profile" available.
> >>
> >> "os" defines the operating system of the agents the configuration will
> >> apply on. For example you can use "Windows" or "Linux":
> >> 
> >>
> >> "name" is the name of an agent. If you want the configuration block to
> >> apply to a specific agent, use this option.
> >> 
> >>
> >> "profile" is a descriptive term that you can use to group agents. The
> >> agent "subscribes" to the profile in its ossec.conf.
> >> I haven't used this option in years, so I don't remember how to use it
> off hand.
> >>
> >>
> >> > Thanks
> >> > Hardik Joshi
> >> >
> >> >
> >>
> >> Hope this helps. Feel free to watch this space for further updates:
> >>
> https://ossec-documentation.readthedocs.io/en/latest/configuration/agent_conf.html
> >>
> >> --
> >>
> >> ---
> >> You received this message because you are subscribed to the Google
> Groups "ossec-list" group.
> >> To unsubscribe from this group and stop receiving emails from it, send
> an email to ossec-list+unsubscr...@googlegroups.com.
> >> To view this discussion on the web visit
> https://groups.google.com/d/msgid/ossec-list/CAMyQvMpvgO9ts1LDQMBNAMYZDM4vbfCxzXcc%2BvaCyeADfP_HoQ%40mail.gmail.com
> .
> >> For more options, visit https://groups.google.com/d/optout.
> >
> > --
> >
> > ---
> > You received this message because you are subscribed to the Google
> Groups "ossec-list" group.
> > To unsubscribe from this group and stop receiving emails from it, send
> an email to ossec-list+unsubscr...@googlegroups.com.
> > To view this discussion on the web visit
> https://groups.google.com/d/msgid/ossec-list/CAFjM2gNzHK7q7T%2Btwmp45DQrbAh01fUVhLX_V5ecuBg1ViVWWg%40mail.gmail.com
> .
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ossec-list+unsubscr...@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/ossec-list/CAMyQvMot6a7tN0VjWTm2A%3DLYWA2mAO0z5GeT0CN7N7AC1Gn1XA%40mail.gmail.com
> .
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/CAFjM2gMYxChx4%3DNBe3Wh0_bW0t2yMqsa5AatTQMep%3D8BPMuF3w%40mail.gmail.com.