On Thu, Jan 15, 2015 at 9:45 AM, Martin Kvocka <
mkv...@gmail.com> wrote:
> Yes, here are two:
>
> ** Alert 1421201008.92848: mail - ossec,syscheck,
> 2015 Jan 14 03:03:28 (hostname) a.b.c.d->syscheck
> Rule: 550 (level 7) -> 'Integrity checksum changed.'
> Integrity checksum changed for: 'C:\Program Files/Microsoft SQL
> Server/MSSQL11.APPS/MSSQL/Log/system_health_0_130655447155770000.xel'
> Size changed from '465920' to '619520'
>
> ** Alert 1421236975.304052: mail - ossec,syscheck,
> 2015 Jan 14 13:02:55 (hostname) a.b.c.d->syscheck
> Rule: 550 (level 7) -> 'Integrity checksum changed.'
> Integrity checksum changed for: 'C:\Program Files/Microsoft SQL
> Server/MSSQL11.APPS/MSSQL/Log/system_health_0_130655447155770000.xel'
> Size changed from '619520' to '773120'
>
Checking the size is a different check than the checksum. If you just