<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Week of OSSEC Day 2: Detecting New Files</title>
	<atom:link href="http://www.immutablesecurity.com/index.php/2009/10/26/week-of-ossec-day-2-detecting-new-files/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.immutablesecurity.com/index.php/2009/10/26/week-of-ossec-day-2-detecting-new-files/</link>
	<description>Information Security, Privacy and Personal Liberty</description>
	<lastBuildDate>Sun, 29 Jan 2012 17:21:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: mstarks</title>
		<link>http://www.immutablesecurity.com/index.php/2009/10/26/week-of-ossec-day-2-detecting-new-files/comment-page-1/#comment-380</link>
		<dc:creator>mstarks</dc:creator>
		<pubDate>Wed, 10 Mar 2010 19:22:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.immutablesecurity.com/?p=229#comment-380</guid>
		<description>&lt;blockquote cite=&quot;#commentbody-377&quot;&gt;
&lt;strong&gt;&lt;a href=&quot;#comment-377&quot; rel=&quot;nofollow&quot;&gt;Devendra&lt;/a&gt; :&lt;/strong&gt;
&lt;p&gt;Another question…will the new file alert gets generated only during next scheduled scan or can it be fired real time if “real time” option is set? It doesnt seems to be working in real time for me.&lt;/p&gt;
&lt;/blockquote&gt;

Hello Devendra,

I could be wrong, but I believe you will get a new file alert in a currently monitored directory upon restarting OSSEC, or in a newly added directory after the next syscheck scan runs.

Regards,
Mike</description>
		<content:encoded><![CDATA[<blockquote cite="#commentbody-377"><p>
<strong><a href="#comment-377" rel="nofollow">Devendra</a> :</strong></p>
<p>Another question…will the new file alert gets generated only during next scheduled scan or can it be fired real time if “real time” option is set? It doesnt seems to be working in real time for me.</p>
</blockquote>
<p>Hello Devendra,</p>
<p>I could be wrong, but I believe you will get a new file alert in a currently monitored directory upon restarting OSSEC, or in a newly added directory after the next syscheck scan runs.</p>
<p>Regards,<br />
Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Devendra</title>
		<link>http://www.immutablesecurity.com/index.php/2009/10/26/week-of-ossec-day-2-detecting-new-files/comment-page-1/#comment-377</link>
		<dc:creator>Devendra</dc:creator>
		<pubDate>Wed, 10 Mar 2010 09:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.immutablesecurity.com/?p=229#comment-377</guid>
		<description>Another question...will the new file alert gets generated only during next scheduled scan or can it be fired real time if &quot;real time&quot; option is set? It doesnt seems to be working in real time for me.</description>
		<content:encoded><![CDATA[<p>Another question&#8230;will the new file alert gets generated only during next scheduled scan or can it be fired real time if &#8220;real time&#8221; option is set? It doesnt seems to be working in real time for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Devendra</title>
		<link>http://www.immutablesecurity.com/index.php/2009/10/26/week-of-ossec-day-2-detecting-new-files/comment-page-1/#comment-376</link>
		<dc:creator>Devendra</dc:creator>
		<pubDate>Wed, 10 Mar 2010 08:32:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.immutablesecurity.com/?p=229#comment-376</guid>
		<description>Please ignore my question. I realized those xml&#039;s are only manager.</description>
		<content:encoded><![CDATA[<p>Please ignore my question. I realized those xml&#8217;s are only manager.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Devendra</title>
		<link>http://www.immutablesecurity.com/index.php/2009/10/26/week-of-ossec-day-2-detecting-new-files/comment-page-1/#comment-375</link>
		<dc:creator>Devendra</dc:creator>
		<pubDate>Wed, 10 Mar 2010 08:23:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.immutablesecurity.com/?p=229#comment-375</guid>
		<description>Are the changes in ossec_rules.xml &amp; local_rules.xml required on the agent host or the manager host to alert on new files ?

Thanks.</description>
		<content:encoded><![CDATA[<p>Are the changes in ossec_rules.xml &amp; local_rules.xml required on the agent host or the manager host to alert on new files ?</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

