Hi Patrick,

On Tue, Jan 11, 2011 at 11:54 AM, Patrick Melvin
<[email protected]> wrote:
> Hello, I've run into another issue after "resolving" the last one.
> The OSSEC server is not sending logs remotely to a log collector.
> ossec-csyslogd shows in the logs that it starts ok, and is configured
> to forward logs via syslog to the IP address specified in the
> ossec.conf.  I've verified that the OSSEC server has connectivity to
> the log collector over 514/udp.  I've also made file changes, etc. to
> monitored files/directories on a Windows appliance that has an agent
> running to test logging, and no logs.
>
> Not sure if this is relevant or not, but alerts.log has been blank
> every day.  I'm also getting an odd log from remoted:
>
> 2011/01/11 11:38:53 ossec-remoted: INFO: Event count after '20000':
> 15594243->6353696 (40%)
>
> Thanks in advance,
> Patrick
>

It looks like you're having more issues than sending syslog. You'll
need to track down why the alerts.log file isn't being logged to.
Are you receiving alert emails?
What are the permissions for /var/ossec/log? And the files inside? The
ossec processes will need write access to the log files.
What ossec processes are running?
Is SELinux installed/enabled? Is it blocking ossec somehow?

Reply via email to