Yes, we have activated logall but it is not a permanent solution because of the disk space.
We found statistical files in "/var/ossec/stats/totals/2019/Sep".
What do these files correspond to? Is there any documentation?
What do these lines correspond to?
11-100003-0-88
11-5402-3-1
11-5501-3-93
11-5502-3-90
11-5722-0-6
11-5715-3-2
11-40700-0-449
11-80070-0-4
11-530-0-136
11-535-1-2
11--871--4487--0--0
The first number seems to correspond to the time, but the others?
In addition, there is this line: hour totals - 11:4487
Should we understand 4487 event or 4 487 000 event?
Regards,
Jérémy