Syscheck Report modif in file ?


Hello, with an ossec agent installed to receive with the syscheck option, changes in a file? And not just the old cheksum and the new one?  With the parameter "report_change="yes" 
As I understand it, With the parameter, as below normally it should give me what was added when I modify a file in / var / log / test1 /?
But it only alerts me of the checksum changed each time without telling me what has changed inside the files..
I can not find the solution ..

  • kgn,

    This is expected behavior. OSSEC checks against a hash of the previous file when looking for changes. it sounds like what you are looking for is actually a file auditing solution, of which there are a number on the market to choose from.
