Hi,

I am deploying OSSEC to my working environment and I am having issue to add 
OSSEC agents more than the default supported number.

I follow this URL 
(http://www.ossec.net/doc/faq/unexpected.html?highlight=maximum#errors-when-dealing-with-multiple-agents)
 and I re-compiled the OSSEC server and I have increased the number of 
supported 
agents to 1024. However, whenever I start the OSSEC server and the number of 
agents over the default value, I see the following errors from the ossec.log.

********************************************************************************
2010/12/10 03:04:47 ossec-remoted(4111): INFO: Maximum number of agents allowed:
 '1024'.
2010/12/10 03:04:47 ossec-remoted(1410): INFO: Reading authentication keys file.
2010/12/10 03:04:48 ossec-remoted: Unable to open agent file. errno: 24
2010/12/10 03:04:48 ossec-remoted(1103): ERROR: Unable to open file '/queue/rids
/248'.
********************************************************************************

Since the ossec-remoted process can't be started and ALL OSSEC agents can't 
talk 
to my server. Once I reduce the number of OSSEC agents below the default value, 
it works fine.

Is there anyone which hits the same problem and how do you solve it?

My OSSEC server is installed on a Sun Solaris 8 machine. 

Best regards,
Marcos


      

Reply via email to