I have configured several paths in <nodiff>...</nodiff> in the
/var/ossec/etc/ossec-server.conf. For example I have
Nevertheless I receive messages with changes like this
Rule: 552 fired (level 7) -> "Integrity checksum changed again (3rd time)."
Portion of the log(s):
Integrity checksum changed for:
I tried putting all such paths delimited with commas on one line between
one pair of <nodiff>...</nodiff> and every path on the line of its own
between its own pair <nodiff>...</nodiff>. The result is the same.
What am I doing wrong?