83ba36bfdecd4201a7062d29488d9aee9966484e
[ossec-hids.git] / debian / ossec-hids / var / ossec / etc / ossec-agent.conf
1 <!-- OSSEC example config -->
2
3 <ossec_config>
4   <client>
5     <server-ip>192.168.10.100</server-ip>
6   </client>
7
8   <syscheck>
9     <!-- Frequency that syscheck is executed (default every 2 hours) -->
10     <frequency>7200</frequency>
11
12     <!-- Directories to check  (perform all possible verifications) -->
13     <directories check_all="yes">/etc,/usr/bin,/usr/sbin</directories>
14     <directories check_all="yes">/bin,/sbin,/boot</directories>
15
16     <!-- Files/directories to ignore -->
17     <ignore>/etc/mtab</ignore>
18     <ignore>/etc/hosts.deny</ignore>
19     <ignore>/etc/mail/statistics</ignore>
20     <ignore>/etc/random-seed</ignore>
21     <ignore>/etc/random.seed</ignore>
22     <ignore>/etc/adjtime</ignore>
23     <ignore>/etc/httpd/logs</ignore>
24
25     <!-- Check the file, but never compute the diff -->
26     <nodiff>/etc/ssl/private.key</nodiff>
27   </syscheck>
28
29   <rootcheck>
30     <rootkit_files>/var/ossec/etc/shared/rootkit_files.txt</rootkit_files>
31     <rootkit_trojans>/var/ossec/etc/shared/rootkit_trojans.txt</rootkit_trojans>
32   </rootcheck>
33
34   <localfile>
35     <log_format>syslog</log_format>
36     <location>/var/log/messages</location>
37   </localfile>
38
39   <localfile>
40     <log_format>syslog</log_format>
41     <location>/var/log/authlog</location>
42   </localfile>
43
44   <localfile>
45     <log_format>syslog</log_format>
46     <location>/var/log/secure</location>
47   </localfile>
48
49   <localfile>
50     <log_format>syslog</log_format>
51     <location>/var/log/xferlog</location>
52   </localfile>
53
54   <localfile>
55     <log_format>syslog</log_format>
56     <location>/var/log/maillog</location>
57   </localfile>
58
59   <localfile>
60     <log_format>apache</log_format>
61     <location>/var/www/logs/access_log</location>
62   </localfile>
63
64   <localfile>
65     <log_format>apache</log_format>
66     <location>/var/www/logs/error_log</location>
67   </localfile>
68 </ossec_config>