On Fri, Nov 19, 2010 at 12:04 PM, x509v3 <[email protected]> wrote:
> I'm really enjoying ossec, but one of the areas that consistently
> confounds me is getting a reliable centralized config working.
>
> The goal is to have as minimal-as-possible ossec.conf on each agent,
> and drive all configs from the ossec master's agent.conf.  I've
> purchased and read the book, followed the many excellent blogs and doc
> pages, but I'm still seeing the following:
>
> The agent is happily communicating with the server, using an
> agent.conf-powered configuration. But I cannot get the agent to update
> its agent.conf (or have the server push an updated one to the agent).
>
> I suspect there's some sort of cache issue or update mechanism that's
> getting bad data and isn't getting the hint to update itself.  Would
> love to hear if there are any other "tricks" to force an agent to grab
> a new config. I'd like to avoid manually updating 100+ agents each
> change.
>
> Anyone know how the agent (or server) determines when the agent's out
> of sync and needs a new update?
>
> In the example below, note that the md5sums do not match. I restarted
> both the server and the agent over 8 hours ago, but they're still out
> of sync.
>
> On the server:
>  ls -al ../etc/shared/agent.conf
> -r--r----- 1 root root 1532 Nov 18 21:50 ../etc/shared/agent.conf
>
> md5sum ../etc/shared/agent.conf
> 8992ebf09a31a8344a9f06180e490fce  ../etc/shared/agent.conf
>
> ./agent_control -i 001
> OSSEC HIDS agent_control. Agent information:
>   Agent ID:   001
>   Agent Name: test200
>   IP address: 10.1.2.89
>   Status:     Active
>
>   Operating system:    Linux test200 2.6.18-128.el5 #1 SMP Wed Dec 17
> 11..
>   Client version:      OSSEC HIDS v2.5.1 /
> b488aae0f9ebf2b96b270b903483b790
>   Last keep alive:     Fri Nov 19 08:45:02 2010
>
>   Syscheck last started  at: Fri Nov 19 01:02:19 2010
>   Rootcheck last started at: Fri Nov 19 02:08:37 2010
>
> On the agent:
> ls -al agent.conf
> -rw-r--r-- 1 root root 1641 Nov 18 21:35 agent.conf
>  md5sum agent.conf
> b488aae0f9ebf2b96b270b903483b790  agent.conf
>
>

Double check your permissions. I don't have access to a setup at the
moment to provide working permissions unfortunately....

Does merged.mg match on both systems?

Is there other "junk" in your /var/ossec/etc/shared directory?
Everything in that directory should get copied across, and directories
seem to cause issues (regular and hidden .directories).

Run the processes in debug mode, I remember seeing a debug message
about requesting a new agent.conf or something.

Reply via email to