<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OSSEC Agent Management configuration in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90741#M6032</link>
    <description>&lt;P&gt;Ok.  Thanks ddpbsd.  I think that part of my concern was, being new to this app, I didn't see any data when I went to the dashboard for it.  But as of right now I'm seeing data.  Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2011 22:24:38 GMT</pubDate>
    <dc:creator>dlynum</dc:creator>
    <dc:date>2011-10-14T22:24:38Z</dc:date>
    <item>
      <title>OSSEC Agent Management configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90736#M6027</link>
      <description>&lt;P&gt;I'm new to OSSEC.  I've got version 2.6 of OSSEC installed, running, and sending me alerts.  Since I'm only monitoring one host with OSSEC, I did a local install.  I'm running Splunk 4.2.3, and your Splunk for OSSEC plugin.  When I went to the Agent Management page, and clicked on "List Agents", I received the message "This OSSEC Server is not configured for agent management."&lt;/P&gt;

&lt;P&gt;How do I configure agent management?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2011 19:05:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90736#M6027</guid>
      <dc:creator>dlynum</dc:creator>
      <dc:date>2011-10-12T19:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: OSSEC Agent Management configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90737#M6028</link>
      <description>&lt;P&gt;"Agents" in this context refers to OSSEC agents. OSSEC agents are systems running OSSEC and reporting log messages, file integrity checksums, and other information to a centralized OSSEC server.&lt;/P&gt;

&lt;P&gt;A local OSSEC install will not have any agents.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2011 00:19:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90737#M6028</guid>
      <dc:creator>ddpbsd</dc:creator>
      <dc:date>2011-10-13T00:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: OSSEC Agent Management configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90738#M6029</link>
      <description>&lt;P&gt;Since I'm only monitoring a single server, would it make any sense for me to add an agent onto it so that I can use Splunk for OSSEC to its potential?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2011 23:37:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90738#M6029</guid>
      <dc:creator>dlynum</dc:creator>
      <dc:date>2011-10-13T23:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: OSSEC Agent Management configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90739#M6030</link>
      <description>&lt;P&gt;That's entirely up to you. If you don't want to monitor another system, adding it as an agent is probably not a good idea.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2011 23:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90739#M6030</guid>
      <dc:creator>ddpbsd</dc:creator>
      <dc:date>2011-10-13T23:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: OSSEC Agent Management configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90740#M6031</link>
      <description>&lt;P&gt;The agent screens in &lt;I&gt;Splunk for OSSEC&lt;/I&gt; are really meant for dealing with OSSEC agent keys, which are used to identify individual remote OSSEC agents and protect data in transit.&lt;/P&gt;

&lt;P&gt;As ddpbsd pointed out, these are really more applicable for multi-system installations. If you are only going to run a single system, the agent management screens will not be particularly useful.&lt;/P&gt;

&lt;P&gt;That said, you configure agent management by creating/editing the file called &lt;CODE&gt;ossec_servers.conf&lt;/CODE&gt; in your &lt;CODE&gt;$SPLUNK_HOME/etc/apps/ossec/local&lt;/CODE&gt; directory. &lt;/P&gt;

&lt;P&gt;Take a look at the &lt;CODE&gt;README&lt;/CODE&gt; file included with Splunk for OSSEC for more detail, and if anything doesn't make sense feel free to ask. But essentially you need to provide a path for Splunk to execute OSSEC's &lt;CODE&gt;manage_agents&lt;/CODE&gt; and &lt;CODE&gt;agent_control&lt;/CODE&gt; commands.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 21:47:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90740#M6031</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2011-10-14T21:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: OSSEC Agent Management configuration</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90741#M6032</link>
      <description>&lt;P&gt;Ok.  Thanks ddpbsd.  I think that part of my concern was, being new to this app, I didn't see any data when I went to the dashboard for it.  But as of right now I'm seeing data.  Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2011 22:24:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/OSSEC-Agent-Management-configuration/m-p/90741#M6032</guid>
      <dc:creator>dlynum</dc:creator>
      <dc:date>2011-10-14T22:24:38Z</dc:date>
    </item>
  </channel>
</rss>

