On Tue, Aug 24, 2010 at 7:15 AM, Aeterna <[email protected]> wrote:
> Hey folks,
>
> I'm looking to deploy ossec on several servers but I'm running into
> 2-3 issues, which hopefully are simple and I'm just overlooking
> something obvious. I'm using 2.4.1 on both server and agent, the
> agent's installed through a binary to make the rollout automated
> through a script.
>

Where did you get the binaries?

> So I've got a server installed and 1 agent who's getting a shared
> config, verified by looking at the md5sum. These are DirectAdmin
> servers so I've included this part to syscheck.
>    <ignore>/etc/virtual/usage/</ignore>
>    <ignore>/etc/virtual/pophosts</ignore>
>    <ignore>/etc/virtual/pophosts_user</ignore>
>    <ignore>/etc/httpd/conf/extra/directadmin-vhosts.conf</ignore>
>    <ignore>/etc/httpd/conf/extra/directadmin-vhosts.conf.back</
> ignore>
>    <ignore>/etc/virtual/domains</ignore>
>    <ignore>/etc/virtual/domainowners</ignore>
>    <ignore>/etc/proftpd.passwd</ignore>
>    <ignore>/etc/proftpd.vhosts.conf</ignore>
>    <ignore>/etc/named.conf</ignore>
>
> Now from what I understand this should stop the agent checking said
> files and directory, however when I run /var/ossec/bin/
> syscheck_control -i (id), it'll still show the /etc/virtual/pophosts &
> pophosts_user files to have been changed.
>

Are you getting email alerts for these files?
Please post your entire agent.conf. I'm wondering if it's not getting used.
Are other configurations in the agent.conf getting used?

> The 2nd issue is that I'm not getting the daily reports e-mailed to
> me, in my /var/ossec/etc/ossec.conf I have added the following:
>
>  <reports>
>    <category>syscheck</category>
>    <title>Daily report: syscheck</title>
>    <email_to>[email protected]</email_to>
>  </reports>
>
> I can see in the /var/ossec/logs/ossec.log that it says after a filter
> had been applied, it contains no alerts... while there clearly were
> alerts that day. It ran at 1minute past midnight, but I'm assuming
> that it still had the alerts in the alerts file at that point.
>
> Then finally I set up another test server on an equal machine/distro
> and decided to try a manual report from the cli and ran this command:
> cat /var/ossec/logs/alerts/alerts.log | /var/ossec/bin/ossec-reportd -
> n "Test summary"
> This generated a summary of the alerts it had during that day, however
> when I ran it on my first server, it just cat'd the alerts log file,
> nothing else.
> Not sure where to look on that one.
>
> Thanks in advance.

There were no error messages at all on the first server when you ran
the report manually? That's odd.
Check the ossec-reportd file and permissions (file
/var/ossec/bin/ossec-reportd ; ls -l /var/ossec/bin/ossec-reportd).
These are the permissions I have for the file:
-r-xr-x---  1 root  ossec  241863 Aug 10 10:23 /var/ossec/bin/ossec-reportd

Reply via email to