Re: [ossec-list] Should I syscheck logfiles ?

2015-04-20 Thread calvinh34
This totally makes sense and comfort me in my initial misleading. Thanks you both for your time. Le vendredi 17 avril 2015 15:05:27 UTC+2, dan (ddpbsd) a écrit : On Fri, Apr 17, 2015 at 8:50 AM, calv...@gmail.com javascript: wrote: Hello I think the question is pretty

Re: [ossec-list] Should I syscheck logfiles ?

2015-04-17 Thread dan (ddp)
On Fri, Apr 17, 2015 at 8:50 AM, calvin...@gmail.com wrote: Hello I think the question is pretty self-explainatory, but let me elaborate : regarding of PCIDSS requirement about File Monitoring Integrity, I set syscheck to monitor my application logfiles. Problem is that these files are

RE: [ossec-list] Should I syscheck logfiles ?

2015-04-17 Thread LostInTheTubez
IANA QSA. The way I interpret 10.5.5 is you should monitor ARCHIVED log files to ensure no one tampers with them. Monitoring live log files is arguably pointless, as they are (usually) constantly changing. You should monitor your archived logs and your security sensitive program files. It