On Fri, Jul 22, 2016 at 2:44 PM, EvilZ <
laque...@gmail.com> wrote:
> ok not a problem,
>
> just to make sure, when you launch the script ossec-syscheckd does it inform
> you that it is disabled ?
>
AGENT:
root@ossec283-agent:~/ossec-hids-2.8.3/src# pkill ossec-syscheckd
root@ossec283-agent:~/ossec-hids-2.8.3/src# ps auxww | grep ossec-syscheckd
root 21118 0.0 0.0 8860 648 ? S+ 18:48 0:00 grep
--color=auto ossec-syscheckd
root@ossec283-agent:~/ossec-hids-2.8.3/src# /var/ossec/bin/ossec-syscheckd -df
2016/07/22 18:48:17 ossec-syscheckd: DEBUG: Starting ...
2016/07/22 18:48:17 ossec-rootcheck: DEBUG: Starting ...
2016/07/22 18:48:17 ossec-rootcheck: Starting queue ...
2016/07/22 18:48:17 ossec-syscheckd: INFO: (unix_domain) Maximum send
buffer set to: '212992'.
2016/07/22 18:48:21 ossec-syscheckd: INFO: (unix_domain) Maximum send
buffer set to: '212992'.
2016/07/22 18:48:21 ossec-syscheckd: INFO: Started (pid: 21119).
2016/07/22 18:48:21 ossec-rootcheck: INFO: Started (pid: 21119).
2016/07/22 18:48:21 ossec-syscheckd: INFO: Monitoring directory: '/var/test'.
2016/07/22 18:48:21 ossec-syscheckd: INFO: Monitoring directory:
'/var/ossec/etc'.
SERVER:
root@ossec283-server:/var/ossec/queue/syscheck# pkill ossec-syscheckd
root@ossec283-server:/var/ossec/queue/syscheck# ps auxww | grep syscheck
root 25897 0.0 0.0 8860 644 ? S+ 18:48 0:00 grep
--color=auto syscheck
root@ossec283-server:/var/ossec/queue/syscheck#
/var/ossec/bin/ossec-syscheckd -df
2016/07/22 18:48:50 ossec-syscheckd: DEBUG: Starting ...
2016/07/22 18:48:50 ossec-rootcheck: DEBUG: Starting ...
2016/07/22 18:48:50 ossec-rootcheck: Starting queue ...
2016/07/22 18:48:50 ossec-syscheckd: INFO: (unix_domain) Maximum send
buffer set to: '212992'.
2016/07/22 18:48:54 ossec-syscheckd: INFO: (unix_domain) Maximum send
buffer set to: '212992'.
2016/07/22 18:48:54 ossec-syscheckd: INFO: Started (pid: 25898).
2016/07/22 18:48:54 ossec-rootcheck: INFO: Started (pid: 25898).
2016/07/22 18:48:54 ossec-syscheckd: INFO: Monitoring directory: '/etc'.
2016/07/22 18:48:54 ossec-syscheckd: INFO: Monitoring directory: '/usr/bin'.
2016/07/22 18:48:54 ossec-syscheckd: INFO: Monitoring directory: '/usr/sbin'.
2016/07/22 18:48:54 ossec-syscheckd: INFO: Monitoring directory: '/bin'.
2016/07/22 18:48:54 ossec-syscheckd: INFO: Monitoring directory: '/sbin'.