@scottalanmiller said in Distro Selection for OSSEC:
Running 6.7 isn't a very secure way to go about things. That means that they are not patching... like more or less the most basic thing you do in security!!
Well, I think they just aren't patching the pre-built OVA. They have later releases of the OSSEC server version from what I saw. And if I were deploying it, I would just install the bits on my own Linux server rather than use the OVA.
That way if this is used in production at some point (I mean Hyper-V and not your lab gear), you will be ready for a complete re-install if absolutely needed in a DR scenario.