I know a lot of us use puppet to deploy OSSEC.. Just wondering if anyone has bothered to put together rules for puppet alerts? Things like when a file changes -- can be useful if you are not using syscheck on that file, or if you want a correlation with the file change and what changed it.
Lots of other things come to mind and I have begun this process, but if someone else has already done it - well, I just thought I would ask. cheers Kat