have you been check /etc/group for ossec:x:501:apache or ossec:x:501:www in my server ossec:x:501:www ->ossec:x:501:apache
for reference ----- Original Message ----- From: "Wilson, Walter" <[EMAIL PROTECTED]> To: <[email protected]> Sent: Tuesday, December 18, 2007 2:28 AM Subject: [ossec-list] Re: OSSEC-WUI Daniel, Thanks but I may have confused you. The Web-ui always shows 'Agent not found' even though there are two agents listed in /var/ossec/queue/agent-info/ I added the localhost agent because I was sure I had read somewhere about it - of course I cannot find it anywhere now. It appears the web-ui cannot read any data so I'm thinking along the lines of permissions. I've given read to 'others' in all the appropriate ossec directories but it seems to make no difference. Ideas anyone? Regards, Walter Wilson Group Network and Security Manager ISD V.Ships (UK) Ltd DDI: +44 141 305 7771 Main: +44 141 243 2435 -----Original Message----- From: [email protected] [mailto:[EMAIL PROTECTED] On Behalf Of Daniel Cid Sent: 15 December 2007 02:34 To: [email protected] Subject: [ossec-list] Re: OSSEC-WUI Hi, The web ui will only show the agents that were able to at least once connect to the server. It reads the contents from /var/ossec/queue/agent-info/ , so if you added a fake agent it will not show up in there. Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On Dec 7, 2007 12:25 PM, Wilson, Walter <[EMAIL PROTECTED]> wrote: > > > > > Pretty new to OSSEC/Linux > > > > I've been running OSSEC 1.4 on Debian Sarge successfully for a few months > and like it. > > > > Thought I'd have a look at the web front end (v2.0) but on 'Main' I get the > message: 'Agent not found', the search etc. receives 'no results' > > > > I've created an agent for the localhost (seems daft but I did it anyway..) > without any difference. > > > > Any help would be appreciated > > > > Regards, > > > > Walter Wilson > > Group Network and Security Manager > > ISD > > V.Ships (UK) Ltd > > > > DDI: +44 141 305 7771 > > Main: +44 141 243 2435 > > > > > > ************************************************************************ ************************************ > This email is confidential and intended solely for the use of the individual > to whom it is addressed. If you are not the intended recipient, be advised > that you have received this email in error and that any use, dissemination, > forwarding, printing or copying of this email is strictly prohibited. If you > have received this email in error please contact the sender. > > P We only print the emails we really need to ________________________________________________________________________ This email has been scanned for all viruses by the MessageLabs Email Security System. ________________________________________________________________________ ************************************************************************************************************ This email is confidential and intended solely for the use of the individual to whom it is addressed. If you are not the intended recipient, be advised that you have received this email in error and that any use, dissemination, forwarding, printing or copying of this email is strictly prohibited. If you have received this email in error please contact the sender. We only print the emails we really need to
