Update: Recompiled cleaned up the segfault and port 1514 is back on- line. Not sure what happened to cause, but needing to move on...
The current major issue is getting beyond what seems to be a hard limit of 1025 clients, even though I set the 'setmaxagents' to 4096. We are using a script to parse through a colon-delimited list of servername:IPadress to add agents -- front-end to 'manage-agents'. But when it goes to add agents higher than 1025 the ability to go beyond that the self-generated ID fails. Is 1025 the real client limit? Thanks, Patrick On Jun 22, 10:21 am, HouseofSwartz <[email protected]> wrote: > Update: Figured out the remoted issue, we didn't have a <allowed-ips> > listed in our config file. Not sure if it is required for our setup. > However, now the real issue is that port 1514 isn't showing up in > netstat. And even worse is this in /var/log/messages - > Jun 22 10:53:05 n1pvir006 kernel: ossec-remoted[5144]: segfault at > 0000000000002031 rip 000000000041dedb rsp 00007fff30c55a90 error 4 > > What would be the best way to fix this error? Re-install? > > Please help!! > > Thanks, > Patrick > > On Jun 21, 10:36 pm, HouseofSwartz <[email protected]> > wrote: > > > Hello and thank you in advance for any help given... > > > I have two issues and not sure if they are related. > > First, following Daniel's advice (thank you Daniel) we set > > "setmaxagents" to 4096 and compiled cleanly. However, after adding > > the first 1024 clients we now get this error: > > - Adding a new agent (use '\q' to return to the main menu). > > Please provide the following: > > * A name for the new agent: * The IP Address of the new > > agent: * An ID for the new agent[1025]: > > ** ID '1025' already present. They must be unique. > > > Looking at our client.keys file there isn't an ID of 1025. > > > Second, looking at our log file it appears that 'remoted' is not happy > > ---- > > > 2009/06/21 22:51:58 ossec-remoted: INFO: Started (pid: 12344). > > 2009/06/21 22:51:58 ossec-remoted(1501): ERROR: No IP or network > > allowed in the access list for syslog. No reason for running it. > > Exiting. > > 2009/06/21 22:51:58 ossec-rootcheck: Rootcheck disabled. Exiting. > > 2009/06/21 22:51:58 ossec-syscheckd: WARN: Rootcheck module disabled. > > 2009/06/21 22:51:58 ossec-monitord: INFO: Started (pid: 12354). > > 2009/06/21 22:51:58 ossec-remoted: INFO: Started (pid: 12346). > > 2009/06/21 22:51:58 ossec-remoted(4111): INFO: Maximum number of > > agents allowed: '4096'. > > 2009/06/21 22:51:58 ossec-remoted(1410): INFO: Reading authentication > > keys file. > > 2009/06/21 22:51:59 ossec-syscheckd: socketerr (not available). > > 2009/06/21 22:51:59 ossec-syscheckd(1224): ERROR: Error sending > > message to queue. > > 2009/06/21 22:51:59 ossec-logcollector: socketerr (not available). > > 2009/06/21 22:51:59 ossec-logcollector(1224): ERROR: Error sending > > message to queue. > > 2009/06/21 22:52:02 ossec-syscheckd: INFO: Started (pid: 12350). > > 2009/06/21 22:52:04 ossec-logcollector(1950): INFO: Analyzing file: '/ > > var/log/messages'. > > 2009/06/21 22:52:04 ossec-logcollector(1950): INFO: Analyzing file: '/ > > var/log/mail.info'. > > 2009/06/21 22:52:04 ossec-logcollector: INFO: Started (pid: 12340). > > 2009/06/21 22:53:38 ossec-syscheckd: INFO: Ending syscheck scan (db). > > 2009/06/21 22:59:31 ossec-syscheckd: INFO: Starting syscheck scan > > (db). > > 2009/06/21 23:09:15 agent_control(1207): ERROR: Unable to switch to > > group: 'ossec'. > > 2009/06/21 23:09:30 agent_control(1210): ERROR: Queue '/queue/alerts/ > > ar' not accessible: 'Connection refused'. > > 2009/06/21 23:09:30 agent_control(1301): ERROR: Unable to connect to > > active response queue. > > > Here is our 'ossec-init.conf' > > os...@n1pvir006 > cat ossec-init.conf > > DIRECTORY="/opt/ossec" > > VERSION="v2.0" > > DATE="Wed May 13 12:18:41 EDT 2009" > > TYPE="server" > > > So, should we be able to go beyond the 1024 clients currently > > configured? > > And, is the 'remoted(1501): ERROR" something fixable? > > > Please let me know what other information would be helpful in > > resolving this issue.
