Hi, I am deploying OSSEC to my working environment and I am having issue to add OSSEC agents more than the default supported number.
I follow this URL (http://www.ossec.net/doc/faq/unexpected.html?highlight=maximum#errors-when-dealing-with-multiple-agents) and I re-compiled the OSSEC server and I have increased the number of supported agents to 1024. However, whenever I start the OSSEC server and the number of agents over the default value, I see the following errors from the ossec.log. ******************************************************************************** 2010/12/10 03:04:47 ossec-remoted(4111): INFO: Maximum number of agents allowed: '1024'. 2010/12/10 03:04:47 ossec-remoted(1410): INFO: Reading authentication keys file. 2010/12/10 03:04:48 ossec-remoted: Unable to open agent file. errno: 24 2010/12/10 03:04:48 ossec-remoted(1103): ERROR: Unable to open file '/queue/rids /248'. ******************************************************************************** Since the ossec-remoted process can't be started and ALL OSSEC agents can't talk to my server. Once I reduce the number of OSSEC agents below the default value, it works fine. Is there anyone which hits the same problem and how do you solve it? My OSSEC server is installed on a Sun Solaris 8 machine. Best regards, Marcos
