diff --git a/Linux/deployment/wazuh-manager/files/local_rules.xml b/Linux/deployment/wazuh-manager/files/local_rules.xml index 753a189..b37bc83 100644 --- a/Linux/deployment/wazuh-manager/files/local_rules.xml +++ b/Linux/deployment/wazuh-manager/files/local_rules.xml @@ -36,25 +36,26 @@ - + syscheck /root/.viminfo modified viminfo (vim history file) updated - + + syscheck + /etc/resolv.conf + resolv.conf modified, big whoop + + + syscheck modified|added|deleted ^/etc/cron. File changed inside Cron! - - syscheck - /etc/resolv.conf - resolv.conf modified, big whoop - syscheck @@ -133,9 +134,9 @@ - + 24001 - already\srunning + already running osquery already running