Maintenance
Configure log rotation:
/var/ossec/logs/alerts/alerts.log {
daily
rotate 30
compress
delaycompress
missingok
notifempty
create 0640 ossec ossec
postrotate
/var/ossec/bin/ossec-control restart > /dev/null 2>&1 || true
endscript
}Database cleanup:
sudo /var/ossec/bin/ossec-control stop
sudo rm -rf /var/ossec/queue/alerts/*
sudo rm -rf /var/ossec/queue/diff/*
sudo /var/ossec/bin/ossec-control start