Skip to content

Commit 042ea69

Browse files
author
Manuel J. Bernal
authored
Merge pull request #175 from wazuh/feature-164-define-whodata
Parameterize `whodata` and `realtime` and add related dependencies
2 parents fc502a2 + 1476bf3 commit 042ea69

File tree

5 files changed

+162
-123
lines changed

5 files changed

+162
-123
lines changed

manifests/agent.pp

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -127,6 +127,8 @@
127127
$ossec_syscheck_auto_ignore = $wazuh::params_agent::ossec_syscheck_auto_ignore,
128128
$ossec_syscheck_directories_1 = $wazuh::params_agent::ossec_syscheck_directories_1,
129129
$ossec_syscheck_directories_2 = $wazuh::params_agent::ossec_syscheck_directories_2,
130+
$ossec_syscheck_whodata = $wazuh::params_agent::ossec_syscheck_whodata,
131+
$ossec_syscheck_realtime = $wazuh::params_agent::ossec_syscheck_realtime,
130132
$ossec_syscheck_ignore_list = $wazuh::params_agent::ossec_syscheck_ignore_list,
131133
$ossec_syscheck_ignore_type_1 = $wazuh::params_agent::ossec_syscheck_ignore_type_1,
132134
$ossec_syscheck_ignore_type_2 = $wazuh::params_agent::ossec_syscheck_ignore_type_2,
@@ -151,6 +153,17 @@
151153
validate_string($agent_package_name)
152154
validate_string($agent_service_name)
153155

156+
if($ossec_syscheck_whodata == '"yes"') { # Install Audit if whodata is enabled
157+
package { 'Installing Audit...':
158+
name => "audit",
159+
}
160+
service { auditd:
161+
ensure => running,
162+
enable => true,
163+
}
164+
}
165+
166+
154167
if $manage_client_keys == 'yes' {
155168
if $wazuh_register_endpoint == undef {
156169
fail('The $wazuh_register_endpoint parameter is needed in order to register the Agent.')

manifests/manager.pp

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -156,6 +156,8 @@
156156
$ossec_syscheck_auto_ignore = $wazuh::params_manager::ossec_syscheck_auto_ignore,
157157
$ossec_syscheck_directories_1 = $wazuh::params_manager::ossec_syscheck_directories_1,
158158
$ossec_syscheck_directories_2 = $wazuh::params_manager::ossec_syscheck_directories_2,
159+
$ossec_syscheck_whodata = $wazuh::params_manager::ossec_syscheck_whodata,
160+
$ossec_syscheck_realtime = $wazuh::params_manager::ossec_syscheck_realtime,
159161
$ossec_syscheck_ignore_list = $wazuh::params_manager::ossec_syscheck_ignore_list,
160162

161163
$ossec_syscheck_ignore_type_1 = $wazuh::params_manager::ossec_syscheck_ignore_type_1,
@@ -220,6 +222,17 @@
220222
}
221223
}
222224

225+
226+
if($ossec_syscheck_whodata == '"yes"') { # Install Audit if whodata is enabled
227+
package { 'Installing Auditd...':
228+
name => "audit",
229+
}
230+
service { auditd:
231+
ensure => running,
232+
enable => true,
233+
}
234+
}
235+
223236
# This allows arrays of integers, sadly
224237
# (commented due to stdlib version requirement)
225238
if ($ossec_emailnotification == true) {
@@ -513,4 +526,13 @@
513526
'ESTABLISHED'],
514527
}
515528
}
529+
530+
if($ossec_syscheck_whodata == '"yes"') {
531+
exec { 'Ensure wazuh-fim rule is added to auditctl':
532+
command => "/sbin/auditctl -l",
533+
unless => "/sbin/auditctl -l | grep wazuh_fim",
534+
tries => 2
535+
}
536+
}
537+
516538
}

manifests/params_agent.pp

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -150,6 +150,8 @@
150150
$ossec_syscheck_auto_ignore = undef
151151
$ossec_syscheck_directories_1 = '/etc,/usr/bin,/usr/sbin'
152152
$ossec_syscheck_directories_2 = '/bin,/sbin,/boot'
153+
$ossec_syscheck_whodata = '"no"'
154+
$ossec_syscheck_realtime = '"no"'
153155
$ossec_syscheck_ignore_list = ['/etc/mtab',
154156
'/etc/hosts.deny',
155157
'/etc/mail/statistics',

manifests/params_manager.pp

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -159,6 +159,8 @@
159159
$ossec_syscheck_auto_ignore = 'no'
160160
$ossec_syscheck_directories_1 = '/etc,/usr/bin,/usr/sbin'
161161
$ossec_syscheck_directories_2 = '/bin,/sbin,/boot'
162+
$ossec_syscheck_whodata = '"no"'
163+
$ossec_syscheck_realtime = '"no"'
162164
$ossec_syscheck_ignore_list = ['/etc/mtab',
163165
'/etc/hosts.deny',
164166
'/etc/mail/statistics',

templates/fragments/_syscheck.erb

Lines changed: 123 additions & 123 deletions
Original file line numberDiff line numberDiff line change
@@ -1,128 +1,128 @@
1-
<%- if @kernel == 'windows' -%>
2-
<syscheck> <!-- Default files to be monitored - system32 only. -->
3-
<directories check_all="yes">%WINDIR%/win.ini</directories>
4-
<directories check_all="yes">%WINDIR%/system.ini</directories>
5-
<directories check_all="yes">C:\autoexec.bat</directories>
6-
<directories check_all="yes">C:\config.sys</directories>
7-
<directories check_all="yes">C:\boot.ini</directories>
8-
<directories check_all="yes">%WINDIR%/System32/CONFIG.NT</directories>
9-
<directories check_all="yes">%WINDIR%/System32/AUTOEXEC.NT</directories>
10-
<directories check_all="yes">%WINDIR%/System32/at.exe</directories>
11-
<directories check_all="yes">%WINDIR%/System32/attrib.exe</directories>
12-
<directories check_all="yes">%WINDIR%/System32/cacls.exe</directories>
13-
<directories check_all="yes">%WINDIR%/System32/debug.exe</directories>
14-
<directories check_all="yes">%WINDIR%/System32/drwatson.exe</directories>
15-
<directories check_all="yes">%WINDIR%/System32/drwtsn32.exe</directories>
16-
<directories check_all="yes">%WINDIR%/System32/edlin.exe</directories>
17-
<directories check_all="yes">%WINDIR%/System32/eventcreate.exe</directories>
18-
<directories check_all="yes">%WINDIR%/System32/eventtriggers.exe</directories>
19-
<directories check_all="yes">%WINDIR%/System32/ftp.exe</directories>
20-
<directories check_all="yes">%WINDIR%/System32/net.exe</directories>
21-
<directories check_all="yes">%WINDIR%/System32/net1.exe</directories>
22-
<directories check_all="yes">%WINDIR%/System32/netsh.exe</directories>
23-
<directories check_all="yes">%WINDIR%/System32/rcp.exe</directories>
24-
<directories check_all="yes">%WINDIR%/System32/reg.exe</directories>
25-
<directories check_all="yes">%WINDIR%/regedit.exe</directories>
26-
<directories check_all="yes">%WINDIR%/System32/regedt32.exe</directories>
27-
<directories check_all="yes">%WINDIR%/System32/regsvr32.exe</directories>
28-
<directories check_all="yes">%WINDIR%/System32/rexec.exe</directories>
29-
<directories check_all="yes">%WINDIR%/System32/rsh.exe</directories>
30-
<directories check_all="yes">%WINDIR%/System32/runas.exe</directories>
31-
<directories check_all="yes">%WINDIR%/System32/sc.exe</directories>
32-
<directories check_all="yes">%WINDIR%/System32/subst.exe</directories>
33-
<directories check_all="yes">%WINDIR%/System32/telnet.exe</directories>
34-
<directories check_all="yes">%WINDIR%/System32/tftp.exe</directories>
35-
<directories check_all="yes">%WINDIR%/System32/tlntsvr.exe</directories>
36-
<directories check_all="yes">%WINDIR%/System32/drivers/etc</directories>
37-
<directories check_all="yes" realtime="yes">C:\Documents and Settings/All Users/Start Menu/Programs/Startup</directories>
38-
<directories check_all="yes" realtime="yes">C:\Users/Public/All Users/Microsoft/Windows/Start Menu/Startup</directories>
39-
<ignore type="sregex">.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$</ignore>
1+
<%- if @kernel == 'windows' -%>
2+
<syscheck> <!-- Default files to be monitored - system32 only. -->
3+
<directories check_all="yes">%WINDIR%/win.ini</directories>
4+
<directories check_all="yes">%WINDIR%/system.ini</directories>
5+
<directories check_all="yes">C:\autoexec.bat</directories>
6+
<directories check_all="yes">C:\config.sys</directories>
7+
<directories check_all="yes">C:\boot.ini</directories>
8+
<directories check_all="yes">%WINDIR%/System32/CONFIG.NT</directories>
9+
<directories check_all="yes">%WINDIR%/System32/AUTOEXEC.NT</directories>
10+
<directories check_all="yes">%WINDIR%/System32/at.exe</directories>
11+
<directories check_all="yes">%WINDIR%/System32/attrib.exe</directories>
12+
<directories check_all="yes">%WINDIR%/System32/cacls.exe</directories>
13+
<directories check_all="yes">%WINDIR%/System32/debug.exe</directories>
14+
<directories check_all="yes">%WINDIR%/System32/drwatson.exe</directories>
15+
<directories check_all="yes">%WINDIR%/System32/drwtsn32.exe</directories>
16+
<directories check_all="yes">%WINDIR%/System32/edlin.exe</directories>
17+
<directories check_all="yes">%WINDIR%/System32/eventcreate.exe</directories>
18+
<directories check_all="yes">%WINDIR%/System32/eventtriggers.exe</directories>
19+
<directories check_all="yes">%WINDIR%/System32/ftp.exe</directories>
20+
<directories check_all="yes">%WINDIR%/System32/net.exe</directories>
21+
<directories check_all="yes">%WINDIR%/System32/net1.exe</directories>
22+
<directories check_all="yes">%WINDIR%/System32/netsh.exe</directories>
23+
<directories check_all="yes">%WINDIR%/System32/rcp.exe</directories>
24+
<directories check_all="yes">%WINDIR%/System32/reg.exe</directories>
25+
<directories check_all="yes">%WINDIR%/regedit.exe</directories>
26+
<directories check_all="yes">%WINDIR%/System32/regedt32.exe</directories>
27+
<directories check_all="yes">%WINDIR%/System32/regsvr32.exe</directories>
28+
<directories check_all="yes">%WINDIR%/System32/rexec.exe</directories>
29+
<directories check_all="yes">%WINDIR%/System32/rsh.exe</directories>
30+
<directories check_all="yes">%WINDIR%/System32/runas.exe</directories>
31+
<directories check_all="yes">%WINDIR%/System32/sc.exe</directories>
32+
<directories check_all="yes">%WINDIR%/System32/subst.exe</directories>
33+
<directories check_all="yes">%WINDIR%/System32/telnet.exe</directories>
34+
<directories check_all="yes">%WINDIR%/System32/tftp.exe</directories>
35+
<directories check_all="yes">%WINDIR%/System32/tlntsvr.exe</directories>
36+
<directories check_all="yes">%WINDIR%/System32/drivers/etc</directories>
37+
<directories check_all="yes" realtime="yes">C:\Documents and Settings/All Users/Start Menu/Programs/Startup</directories>
38+
<directories check_all="yes" realtime="yes">C:\Users/Public/All Users/Microsoft/Windows/Start Menu/Startup</directories>
39+
<ignore type="sregex">.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$</ignore>
4040

41-
<!-- Windows registry entries to monitor. -->
42-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\batfile</windows_registry>
43-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\cmdfile</windows_registry>
44-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\comfile</windows_registry>
45-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\exefile</windows_registry>
46-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\piffile</windows_registry>
47-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects</windows_registry>
48-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Directory</windows_registry>
49-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Folder</windows_registry>
50-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Protocols</windows_registry>
51-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Policies</windows_registry>
52-
<windows_registry>HKEY_LOCAL_MACHINE\Security</windows_registry>
53-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer</windows_registry>
54-
<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services</windows_registry>
55-
<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs</windows_registry>
56-
<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg</windows_registry>
57-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</windows_registry>
58-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce</windows_registry>
59-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx</windows_registry>
60-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL</windows_registry>
61-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies</windows_registry>
62-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows</windows_registry>
63-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</windows_registry>
64-
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components</windows_registry>
41+
<!-- Windows registry entries to monitor. -->
42+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\batfile</windows_registry>
43+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\cmdfile</windows_registry>
44+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\comfile</windows_registry>
45+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\exefile</windows_registry>
46+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\piffile</windows_registry>
47+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects</windows_registry>
48+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Directory</windows_registry>
49+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Folder</windows_registry>
50+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Protocols</windows_registry>
51+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Policies</windows_registry>
52+
<windows_registry>HKEY_LOCAL_MACHINE\Security</windows_registry>
53+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer</windows_registry>
54+
<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services</windows_registry>
55+
<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs</windows_registry>
56+
<windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg</windows_registry>
57+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</windows_registry>
58+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce</windows_registry>
59+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx</windows_registry>
60+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL</windows_registry>
61+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies</windows_registry>
62+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows</windows_registry>
63+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon</windows_registry>
64+
<windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components</windows_registry>
6565

66-
<!-- Windows files to ignore (static) -->
67-
<ignore>%WINDIR%/System32/LogFiles</ignore>
68-
<ignore>%WINDIR%/Debug</ignore>
69-
<ignore>%WINDIR%/WindowsUpdate.log</ignore>
70-
<ignore>%WINDIR%/iis6.log</ignore>
71-
<ignore>%WINDIR%/system32/wbem/Logs</ignore>
72-
<ignore>%WINDIR%/system32/wbem/Repository</ignore>
73-
<ignore>%WINDIR%/Prefetch</ignore>
74-
<ignore>%WINDIR%/PCHEALTH/HELPCTR/DataColl</ignore>
75-
<ignore>%WINDIR%/SoftwareDistribution</ignore>
76-
<ignore>%WINDIR%/Temp</ignore>
77-
<ignore>%WINDIR%/system32/config</ignore>
78-
<ignore>%WINDIR%/system32/spool</ignore>
79-
<ignore>%WINDIR%/system32/CatRoot</ignore>
66+
<!-- Windows files to ignore (static) -->
67+
<ignore>%WINDIR%/System32/LogFiles</ignore>
68+
<ignore>%WINDIR%/Debug</ignore>
69+
<ignore>%WINDIR%/WindowsUpdate.log</ignore>
70+
<ignore>%WINDIR%/iis6.log</ignore>
71+
<ignore>%WINDIR%/system32/wbem/Logs</ignore>
72+
<ignore>%WINDIR%/system32/wbem/Repository</ignore>
73+
<ignore>%WINDIR%/Prefetch</ignore>
74+
<ignore>%WINDIR%/PCHEALTH/HELPCTR/DataColl</ignore>
75+
<ignore>%WINDIR%/SoftwareDistribution</ignore>
76+
<ignore>%WINDIR%/Temp</ignore>
77+
<ignore>%WINDIR%/system32/config</ignore>
78+
<ignore>%WINDIR%/system32/spool</ignore>
79+
<ignore>%WINDIR%/system32/CatRoot</ignore>
8080

81-
<!-- Windows registry entries to ignore. -->
82-
<registry_ignore>HKEY_LOCAL_MACHINE\Security\Policy\Secrets</registry_ignore>
83-
<registry_ignore>HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users</registry_ignore>
84-
<registry_ignore type="sregex">\Enum$</registry_ignore>
85-
</syscheck>
81+
<!-- Windows registry entries to ignore. -->
82+
<registry_ignore>HKEY_LOCAL_MACHINE\Security\Policy\Secrets</registry_ignore>
83+
<registry_ignore>HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users</registry_ignore>
84+
<registry_ignore type="sregex">\Enum$</registry_ignore>
85+
</syscheck>
8686

87-
<%- else -%>
88-
<syscheck>
89-
<%- if @ossec_syscheck_disabled -%>
90-
<disabled><%= @ossec_syscheck_disabled %></disabled>
91-
<%- end -%>
92-
<%- if @ossec_syscheck_frequency -%>
93-
<frequency><%=@ossec_syscheck_frequency%></frequency>
94-
<%- end -%>
95-
<%- if @ossec_syscheck_scan_on_start -%>
96-
<scan_on_start><%=@ossec_syscheck_scan_on_start%></scan_on_start>
97-
<%- end -%>
98-
<%- if @ossec_syscheck_alert_new_files -%>
99-
<alert_new_files><%=@ossec_syscheck_alert_new_files%></alert_new_files>
100-
<%- end -%>
101-
<%- if @ossec_syscheck_auto_ignore -%>
102-
<auto_ignore frequency="10" timeframe="3600"><%=@ossec_syscheck_auto_ignore%></auto_ignore>
103-
<%- end -%>
104-
<%- if @ossec_syscheck_directories_1 -%>
105-
<directories check_all="yes"><%=@ossec_syscheck_directories_1%></directories>
106-
<%- end -%>
107-
<%- if @ossec_syscheck_directories_2 -%>
108-
<directories check_all="yes"><%=@ossec_syscheck_directories_2%></directories>
109-
<%- end -%>
110-
<%- if @ossec_syscheck_ignore_list -%>
111-
<%- @ossec_syscheck_ignore_list.each do |ignore_element| -%>
112-
<ignore><%= ignore_element %></ignore>
113-
<%- end -%>
114-
<%- end -%>
115-
<%- if @ossec_syscheck_ignore_type_1 -%>
116-
<ignore type="sregex"><%=@ossec_syscheck_ignore_type_1%></ignore>
117-
<%- end -%>
118-
<%- if @ossec_syscheck_ignore_type_2 -%>
119-
<ignore type="sregex"><%=@ossec_syscheck_ignore_type_2%></ignore>
120-
<%- end -%>
121-
<%- if @ossec_syscheck_nodiff -%>
122-
<nodiff><%=@ossec_syscheck_nodiff%></nodiff>
123-
<%- end -%>
124-
<%- if @ossec_syscheck_skip_nfs -%>
125-
<skip_nfs><%=@ossec_syscheck_skip_nfs%></skip_nfs>
126-
<%- end -%>
127-
</syscheck>
87+
<%- else -%>
88+
<syscheck>
89+
<%- if @ossec_syscheck_disabled -%>
90+
<disabled><%= @ossec_syscheck_disabled %></disabled>
91+
<%- end -%>
92+
<%- if @ossec_syscheck_frequency -%>
93+
<frequency><%=@ossec_syscheck_frequency%></frequency>
94+
<%- end -%>
95+
<%- if @ossec_syscheck_scan_on_start -%>
96+
<scan_on_start><%=@ossec_syscheck_scan_on_start%></scan_on_start>
97+
<%- end -%>
98+
<%- if @ossec_syscheck_alert_new_files -%>
99+
<alert_new_files><%=@ossec_syscheck_alert_new_files%></alert_new_files>
100+
<%- end -%>
101+
<%- if @ossec_syscheck_auto_ignore -%>
102+
<auto_ignore frequency="10" timeframe="3600"><%=@ossec_syscheck_auto_ignore%></auto_ignore>
103+
<%- end -%>
104+
<%- if @ossec_syscheck_directories_1 -%>
105+
<directories check_all="yes" whodata=<%=@ossec_syscheck_whodata%> realtime=<%=@ossec_syscheck_realtime%>><%=@ossec_syscheck_directories_1%></directories>
106+
<%- end -%>
107+
<%- if @ossec_syscheck_directories_2 -%>
108+
<directories check_all="yes" whodata=<%=@ossec_syscheck_whodata%> realtime=<%=@ossec_syscheck_realtime%>><%=@ossec_syscheck_directories_2%></directories>
128109
<%- end -%>
110+
<%- if @ossec_syscheck_ignore_list -%>
111+
<%- @ossec_syscheck_ignore_list.each do |ignore_element| -%>
112+
<ignore><%= ignore_element %></ignore>
113+
<%- end -%>
114+
<%- end -%>
115+
<%- if @ossec_syscheck_ignore_type_1 -%>
116+
<ignore type="sregex"><%=@ossec_syscheck_ignore_type_1%></ignore>
117+
<%- end -%>
118+
<%- if @ossec_syscheck_ignore_type_2 -%>
119+
<ignore type="sregex"><%=@ossec_syscheck_ignore_type_2%></ignore>
120+
<%- end -%>
121+
<%- if @ossec_syscheck_nodiff -%>
122+
<nodiff><%=@ossec_syscheck_nodiff%></nodiff>
123+
<%- end -%>
124+
<%- if @ossec_syscheck_skip_nfs -%>
125+
<skip_nfs><%=@ossec_syscheck_skip_nfs%></skip_nfs>
126+
<%- end -%>
127+
</syscheck>
128+
<%- end -%>

0 commit comments

Comments
 (0)