samhain

  1. -t <arg>, --set-checksum-test=<arg> Set file checking to init, update, or check. Use init to create the database, update to update it, and check to check files against the database.

    TipTIP
     

    Yes, it is normal that update takes much more time than init.

  2. -e <arg>, --set-export-severity=<arg> Set the severity threshold for forwarding messages to the log server. arg may be one of none, debug, info, notice, warn, mark, err, crit, alert.

  3. -r <arg>, --recursion=<arg> Set the default recursion level for directories (0 -- 99).