ossec-control What function does the Jobs have?

2 views
Skip to first unread message

HotteFred

unread,
Nov 24, 2009, 4:39:14 AM11/24/09
to ossec-list
Hi,
if i do a /var/ossec/bin/ossec-control status i become (on Server and
some on Agent) the following Jobs:

ossec-monitored
ossec-logcollector
ossec-remoted
ossec-syscheckd
ossec-analysisd
ossec-maild
ossec-execd
ossec-agentd

and in the ../bin dir are too:
ossec-csyslogd
ossec-dbd

What is the detailed job ob all the Daemons/services?

Thanks
Fred

HotteFred

unread,
Nov 24, 2009, 10:07:34 AM11/24/09
to ossec-list

Sorry, i wanted to say:

> What is the detailed function ob all the Daemons/services?

Thanks

oscar schneider

unread,
Nov 25, 2009, 5:41:57 AM11/25/09
to ossec...@googlegroups.com
Hi,

I'm not sure about this, but I think:

ossec-monitored: ???
ossec-logcollector: is responsible for collecting changes in the logfiles specified in $OSSECDIR$/etc/ossec.conf
ossec-remoted: is responsible for maintaining connections to remote devices (e.g. hosts with the ossec agent installed)
ossec-syscheckd: is responsible for checking file integrity, running syschecks (see ossec feature list for more info)
ossec-analysisd: goes through new logs and compares them with the rules to output alerts
ossec-maild: probably only responsible for generating email notifications and handling smtp connections for sending them
ossec-execd: ???
ossec-agentd: ???


and in the ../bin dir are too:
 
ossec-csyslogd: ???
ossec-dbd: if you have database output enabled, it will speak with the mysql/postgresql db specified in the ossec.onf

What is the detailed job ob all the Daemons/services?

Thanks
Fred

Kind regards,

Oscar

HotteFred

unread,
Nov 25, 2009, 5:55:57 AM11/25/09
to ossec-list
The answer is here:

http://www.ossec.net/wiki/Ossec_logic

byby
Fred
Reply all
Reply to author
Forward
0 new messages