[prev in list] [next in list] [prev in thread] [next in thread] 

List:       ossec-list
Subject:    [ossec-list] Re: Ossec server host entry in lieu of IP address
From:       "Daniel Cid" <daniel.cid () gmail ! com>
Date:       2008-04-21 14:15:55
Message-ID: b92e6f200804210715m2bcf239bi948e2cf8cc226ce3 () mail ! gmail ! com
[Download RAW message or body]


Hi Gagan,

It is certainly possible to do so. You just need to duplicate the
keys, config and rules from one
server to the other (using rsync or any other method). In the agent
side, you can use the
"server-hostname" tag instead of the server-ip to specify the server's host.

Also, on version 1.5, you can have multiple server-ip tags and the
agent will switch to the
other server if one becomes unavailable...

Hope it helps.

--
Daniel B. Cid
dcid ( at ) ossec.net



On Wed, Apr 16, 2008 at 8:55 AM,  <gagan.bhatia2@gmail.com> wrote:
>
>  Dear Mailing list
>
>  There is some query regarding the Ossec Backup connectivity & logging.
>
>  Is it possible to replicate the running ossec services to another
>  server.
>
>  Can we add the host entry in agents in place of the IP address &
>  create a backup ossec server to get it prepared for any hardware/
>  software failures.
>  So that in case of failures we only have to change the host record in
>  DNS and not the IP address on all agents.
>  Can we shift logs & agents connectivity (keys and queues) from one
>  ossec server to another.( So that ossec server should not result as
>  single point of failure)
>
>  Regards
>  Gagan
>
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic