Re: [ossec-list] Force/burst output on apt-get and software updates

2014-06-29 Thread Michael Starks
On 06/28/2014 05:18 AM, Gerard Petersen wrote: Is it acceptable operating procedure for ossec to clean out the database without stopping the agents or is there temporary agent shutdown involved? Yes. Just run ./bin/syscheck_control -u One more thing I noticed. All hits that are not around th

[ossec-list] "level 10 - High amount of POST requests in a small period of time" with ngx_pagespeed

2014-06-29 Thread Chris
Hi list, running OSSEC 2.8 on a debian wheezy server together with NginX 1.6 and the ngx_pagespeed 1.8.31.2 module fires the following OSSEC rule: OSSEC HIDS Notification. 2014 Jun 28 14:45:56