Get list of files Ossec is monitoring

55 views
Skip to first unread message

Andries Jansen

unread,
Jul 18, 2015, 9:38:05 AM7/18/15
to ossec...@googlegroups.com
Can I get a list of log files Ossec is monitoring? I've used some wildcards and I want to know if Ossec is monitoring the right files.

theresa mic-snare

unread,
Jul 18, 2015, 2:46:12 PM7/18/15
to ossec...@googlegroups.com
hi,

you mean as in log analysis or monitoring as in file integrity monitoring (syschecks) ?!
actually everything should be defined in the ossec.conf if i'm not mistaken....

Andries Jansen

unread,
Jul 19, 2015, 1:51:36 PM7/19/15
to ossec...@googlegroups.com
Hello,

Yes I've configured the log files for both log analysis and syscheck in the ossec.conf and shared/agent.conf. But I've used some wildcards (*) in the configuration and I want to be sure if all logfiles are monitored.

So I thought if Ossec can show me a list of files that are monitored by Ossec, then can checked to be sure.

Op zaterdag 18 juli 2015 20:46:12 UTC+2 schreef theresa mic-snare:

dan (ddp)

unread,
Jul 19, 2015, 1:53:51 PM7/19/15
to ossec...@googlegroups.com


On Jul 19, 2015 1:51 PM, "Andries Jansen" <and...@jansen-cws.nl> wrote:
>
> Hello,
>
> Yes I've configured the log files for both log analysis and syscheck in the ossec.conf and shared/agent.conf. But I've used some wildcards (*) in the configuration and I want to be sure if all logfiles are monitored.
>
> So I thought if Ossec can show me a list of files that are monitored by Ossec, then can checked to be sure.
>

The ossec.log usually has enteies about which log files are being mobitored, and the syscheck db has all the files syscheck has seen.

> Op zaterdag 18 juli 2015 20:46:12 UTC+2 schreef theresa mic-snare:
>>
>> hi,
>>
>> you mean as in log analysis or monitoring as in file integrity monitoring (syschecks) ?!
>> actually everything should be defined in the ossec.conf if i'm not mistaken....
>>
>> Am Samstag, 18. Juli 2015 15:38:05 UTC+2 schrieb Andries Jansen:
>>>
>>> Can I get a list of log files Ossec is monitoring? I've used some wildcards and I want to know if Ossec is monitoring the right files.
>

> --
>
> ---
> You received this message because you are subscribed to the Google Groups "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

Santiago Bassett

unread,
Jul 24, 2015, 11:29:01 AM7/24/15
to ossec...@googlegroups.com
Hi Andries,

I would suggest to use "lsof" tool and see if files are being read by ossec-logcollector process. 

Best

--
Reply all
Reply to author
Forward
0 new messages