I created an RPM package to install OSSEC agent 2.4.1 on RHEL 5, using files created with a standard installation from an OSSEC agent.
Updated the original agent to 2.5.1, and then packaged up those files again. When I start the agent I get multiple var/ossec/queue/ossec/queue error messages, both from syscheckd and rootcheck. No additional information in ossec.log I have seen similar posts, pointing at local_rules, but AFAIK local_rules only exists on the master, not the agent. Running out of ideas
