OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
If I create a rule to monitor processes via ossec, I create several rules on the server for multiple processes. How do I configure in the agent, to choose only one process, and in another agent another process?
If I create a rule to monitor processes via ossec, I create several rules on the server for multiple processes. How do I configure in the agent, to choose only one process, and in another agent another process?
Ex: Agent 1: (Monit wordpad.exe)
Ex: Agent 2: (Monit explorer.exe)
Server:
how???