Update: Recompiled cleaned up the segfault and port 1514 is back on-
line.  Not sure what happened to cause, but needing to move on...

The current major issue is getting beyond what seems to be a hard
limit of 1025 clients, even though I set the 'setmaxagents' to 4096.
We are using a script to parse through a colon-delimited list of
servername:IPadress to add agents -- front-end to 'manage-agents'.
But when it goes to add agents higher than 1025 the ability to go
beyond that the self-generated ID fails.

Is 1025 the real client limit?

Thanks,
Patrick

On Jun 22, 10:21 am, HouseofSwartz <[email protected]>
wrote:
> Update:  Figured out the remoted issue, we didn't have a <allowed-ips>
> listed in our config file.  Not sure if it is required for our setup.
> However, now the real issue is that port 1514 isn't showing up in
> netstat.  And even worse is this in /var/log/messages -
> Jun 22 10:53:05 n1pvir006 kernel: ossec-remoted[5144]: segfault at
> 0000000000002031 rip 000000000041dedb rsp 00007fff30c55a90 error 4
>
> What would be the best way to fix this error? Re-install?
>
> Please help!!
>
> Thanks,
> Patrick
>
> On Jun 21, 10:36 pm, HouseofSwartz <[email protected]>
> wrote:
>
> > Hello and thank you in advance for any help given...
>
> > I have two issues and not sure if they are related.
> > First, following Daniel's advice (thank you Daniel) we set
> > "setmaxagents" to 4096 and compiled cleanly.  However, after adding
> > the first 1024 clients we now get this error:
> >     - Adding a new agent (use '\q' to return to the main menu).
> >   Please provide the following:
> >    * A name for the new agent:    * The IP Address of the new
> > agent:    * An ID for the new agent[1025]:
> > ** ID '1025' already present. They must be unique.
>
> > Looking at our client.keys file there isn't an ID of 1025.
>
> > Second, looking at our log file it appears that 'remoted' is not happy
> > ----
>
> > 2009/06/21 22:51:58 ossec-remoted: INFO: Started (pid: 12344).
> > 2009/06/21 22:51:58 ossec-remoted(1501): ERROR: No IP or network
> > allowed in the access list for syslog. No reason for running it.
> > Exiting.
> > 2009/06/21 22:51:58 ossec-rootcheck: Rootcheck disabled. Exiting.
> > 2009/06/21 22:51:58 ossec-syscheckd: WARN: Rootcheck module disabled.
> > 2009/06/21 22:51:58 ossec-monitord: INFO: Started (pid: 12354).
> > 2009/06/21 22:51:58 ossec-remoted: INFO: Started (pid: 12346).
> > 2009/06/21 22:51:58 ossec-remoted(4111): INFO: Maximum number of
> > agents allowed: '4096'.
> > 2009/06/21 22:51:58 ossec-remoted(1410): INFO: Reading authentication
> > keys file.
> > 2009/06/21 22:51:59 ossec-syscheckd: socketerr (not available).
> > 2009/06/21 22:51:59 ossec-syscheckd(1224): ERROR: Error sending
> > message to queue.
> > 2009/06/21 22:51:59 ossec-logcollector: socketerr (not available).
> > 2009/06/21 22:51:59 ossec-logcollector(1224): ERROR: Error sending
> > message to queue.
> > 2009/06/21 22:52:02 ossec-syscheckd: INFO: Started (pid: 12350).
> > 2009/06/21 22:52:04 ossec-logcollector(1950): INFO: Analyzing file: '/
> > var/log/messages'.
> > 2009/06/21 22:52:04 ossec-logcollector(1950): INFO: Analyzing file: '/
> > var/log/mail.info'.
> > 2009/06/21 22:52:04 ossec-logcollector: INFO: Started (pid: 12340).
> > 2009/06/21 22:53:38 ossec-syscheckd: INFO: Ending syscheck scan (db).
> > 2009/06/21 22:59:31 ossec-syscheckd: INFO: Starting syscheck scan
> > (db).
> > 2009/06/21 23:09:15 agent_control(1207): ERROR: Unable to switch to
> > group: 'ossec'.
> > 2009/06/21 23:09:30 agent_control(1210): ERROR: Queue '/queue/alerts/
> > ar' not accessible: 'Connection refused'.
> > 2009/06/21 23:09:30 agent_control(1301): ERROR: Unable to connect to
> > active response queue.
>
> > Here is our 'ossec-init.conf'
> > os...@n1pvir006 > cat ossec-init.conf
> > DIRECTORY="/opt/ossec"
> > VERSION="v2.0"
> > DATE="Wed May 13 12:18:41 EDT 2009"
> > TYPE="server"
>
> > So, should we be able to go beyond the 1024 clients currently
> > configured?
> > And, is the 'remoted(1501): ERROR" something fixable?
>
> > Please let me know what other information would be helpful in
> > resolving this issue.

Reply via email to