-
Notifications
You must be signed in to change notification settings - Fork 521
Wazuh 3.6.1 #708
Comments
Hi Doug, First off, huge thanks for a great NSM distro. Is this standard OSSEC 2.9 or the Wazuh fork of OSSEC? If it's the plain old OSSEC, I'd suggest you check out what the Wazuh HIDS folks are doing to enhance OSSEC. P.S. I have "upgraded" the Security 14.0.4.1 OSSEC in-place to the Wazuh fork of OSSEC 2.9 and it works correctly with ELSA, etc. I simply followed the steps here to install on top of the SO OSSEC: Installing Wazuh HIDS. |
Hi adigiuseppe, This hasn't been implemented yet since OSSEC 2.9 hasn't been released. Once it is released, I'll take a look at standard OSSEC vs Wazuh. |
OK, I ask because Wazuh is forked off the OSSEC 2.9 code branch already; they also contribute back to the upstream OSSEC project, I believe. |
Notes for packaging:
https://groups.google.com/d/topic/ossec-list/xiVOGEBqTVg/discussion |
Another note for packaging: ossec-server.conf should have |
I'd really like to see Wazuh in security onion. It already is integrated with the ELK stack, and it seems like you are headed there anyway. I'd love to see this in a future release of security onion. |
submitted for testing: |
Need the new OSSEC agent to parse EventChannel logs properly (for sysmon).
The text was updated successfully, but these errors were encountered: