-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
syscheck #2097
Comments
Hey, I think you have misunderstood the functionality of syscheck/file integrity monitoring. Syscheck monitors the checksum of files and reports that something has changed. It doesn't tell you who changed something. To get the information you need, you have to combine different logs, e.g. syscheck alerts and an output of e.g. "last" linux command. This is something a SOC analyst would do. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hello! Can you please tell me how to fix the error? I have file integrity control configured. A warning appears when the file is modified. But the warning does not include the computer name or IP address. Other alerts have an ip address. What do I need to change to make the ip address appear?
Received from: ossec->syscheck
Rule: 550 hits (level 7) -> "Integrity checksum changed".
The text was updated successfully, but these errors were encountered: