[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Re: Syscheck enhancements
- To: ossec-list@xxxxxxxxxxxxxxxx
- Subject: [ossec-list] Re: Syscheck enhancements
- From: "Daniel Cid" <daniel.cid@xxxxxxxxx>
- Date: Tue, 2 Oct 2007 21:49:50 -0300
- Authentication-results: mx.google.com; spf=pass (google.com: domain of daniel.cid@xxxxxxxxx designates 66.249.82.224 as permitted sender) smtp.mail=daniel.cid@xxxxxxxxx; dkim=pass (test mode) header.i=@xxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; bh=5QXcKJKCXGIUtmOnTD0bjyzOGYF8UC0y5QVEcUgj5dw=; b=UQrVO3yL0DvFA07SapSl/2KyM6XkC9WJ4fZR8pYSqE4ep8F5SldH//N6WtIeUzEnUKcS+vd0B9OzBzFJ7Fjdy3nHF8FFoNe74osaWMKmV9qGxSPxUiF6ZOLVUG426YD4nsJuIobRcdxuVTAkYZN47x44eAgoMCD52QfQc6Us2lA=
Hi Nick,
Reply inline...
On 10/2/07, Consolo, Nick <nconsolo@xxxxxxxx> wrote:
>
> Hello,
>
> First of all thanks for all the work on ossec. It's a great product. I
> have two questions regarding the syscheck portion of the product.
Thanks :) I am glad you are enjoying it.
> 1. In the syscheck database it is recording the uid and gid of each
> file entered. Is it possible to modify the notifications to include these
> in file modification and creation notifications?
Currently it is not possible, but it is in our TODO list to add
support for it...Just wait
a few months :)
> 2. Is it possible to run the syscheck daemon in an active mode so it
> detects new files instantly, instead of running it periodically to detect
> them?
No, it is not possible. It would require some kernel (lkm) changes to
be notified on every new addition to the monitored directories.. I
know it is possible to do on Windows, but on
Linux, BSD's (and similars), it would require kernel hacking... Anyone
interested in taking
such a task? :)
Thanks,
--
Daniel B. Cid
dcid ( at ) ossec.net
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.