4.3.0 #2299
atomicturtle
announced in
Announcements
4.3.0
#2299
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
OSSEC changelog (4.3.0) support@atomicorp.com
Release Maintainers
Scott R. Shinn (https://www.atomicorp.com)
Contributors on this release
Release Notes
OSSEC 4.3.0 adds three main capabilities; other enhancements and fixes are listed below.
agent_control -M(enable,disable,status,endwith-u <id>). While enabled, syscheck accepts file changes into the baseline without generating integrity alerts.endrestarts syscheck/rootcheck and clears maintenance when that scan finishes (syscheck/rootcheck during OS patching #677, syscheck logs even after restart sometimes #1289, syscheck and OS patching #1681).syslog_output—ossec-csyslogdsupports TCP and optional TLS (protocol,tls,tls_verify,tls_ca) in addition to UDP. Alert payloads (default/CEF/JSON/Splunk) may use up toOS_MAXSTRinstead of a 2048-byte limit (Long syslog messages being truncated when forwarded by syslog_output to graylog. #1762).modsec-auditlocalfile format, and decode nginx ModSecurity error-log events with new rules (Support for modsecurity's /var/log/modsec_audit.log #1390).General
-f -to bulk-load agents from stdin (make manage_agents accept stdin with -f #459)###trailing comments in CDB list text files (Comments in CDB #1527)modsec-auditlog format) plus nginx error-log ModSecurity decoders/rules (Support for modsecurity's /var/log/modsec_audit.log #1390)-r -u(Syscheck_control not failing on invalid arguements #462)Bug Fixes
<frequency>under realtimeusername(alias ofuser), fall back to srcuser, and document fixed script argv (Problem with decoders #2104)This discussion was created from the release 4.3.0.
All reactions