--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/c2049a17-8dd7-4ffb-ae01-e272e1614cbb%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Hi Robert,
You can run update_ruleset.py with the parameter -o ’new path’ to give a different path, by default the path is /var/ossec.
[root@manager ossec]# /var/ossec/bin/update_ruleset.py -h
Update ruleset v3.0.0
Github repository: https://github.com/wazuh/wazuh-ruleset
Full documentation: http://documentation.wazuh.com/en/latest/wazuh_ruleset.html
Usage: ./update_ruleset.py # Update Decoders, Rules and Rootchecks
./update_ruleset.py -b # Restore last backup
Restart:
-r, --restart Restart OSSEC when required.
-R, --no-restart Do not restart OSSEC when required.
Backups:
-b , --backups Restore last backup.
Additional Params:
-f, --force-update Force to update the ruleset. By default, only it is updated the new/changed decoders/rules/rootchecks.
-o, --ossec-path Set OSSEC path. Default: '/var/ossec'
-s, --source Select ruleset source path (instead of download it).
-j, --json JSON output. It should be used with '-s' or '-S' argument.
-d, --debug Debug mode.
-u, --url URL of ruleset zip (default: https://github.com/wazuh/wazuh-ruleset/archive/stable.zip)
[root@manager ossec]#
On August 2, 2017 at 6:08:21 PM, Robert H (rhe...@proficio.com) wrote:
update_ruleset.py
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/b7d728f0-115f-401c-a983-47d6d5f5a604%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/4493ba98-5158-4905-9eaf-f974f16765eb%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d7615dc1-5144-4efe-8153-e797fac6af3d%40googlegroups.com.
<decoder_exclude>ruleset/decoders/0310-ssh_decoders.xml</decoder_exclude>
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d1acd8aa-7eee-4bb0-b09a-dbb03689a194%40googlegroups.com.