My OSSEC server stopped processing these alerts as of midnight last night. I noticed that logs timestamps are not changing. I don't know how the OSSEC agent looks for the logs because I've told the agent to look at *.log in the c:\windows\system32\dhcp folder. It successfully processed Wednesday-Sunday's logs and then stopped. Once I restarted the DHCP service, the timestamp on the log updated and OSSEC started processing the logs and alerting as it should.
I've added an entry in the ossec.conf file on the DHCP server for each day's log and restarted the agent. I don't think this is going to help but we'll see...
