Re: [ossec-list] Alerts forwarded to syslog do not have group information

2017-02-28 Thread David G. Pullman
On Thursday, February 23, 2017 at 1:48:44 PM UTC-5, dan (ddpbsd) wrote: > > Without looking, I'm guessing it isn't included due to the limited > amount of space available for the syslog forwarding. > > > Thanks Dan. I've read briefly in some references about syslog protocol and UDP constraints,

[ossec-list] syscheckd causing soft lockups

2017-02-28 Thread John Gelnaw
Was running wazuh 2.8.1 agent on "most" systems, with the wazuh ossec docker container for a master server. Upgraded to 2.8.3 to try to resolve this problem, with no luck. Out of about 160 machines, 4-5 of them will reliably wedge themselves after some amount of time with messages akin to: