Mike, You mentioned in the realtime thread that you got the agent working. Did deleting the rids files fix this or was it something else? Thanks
On Mon, Jan 24, 2011 at 4:30 PM, dan (ddp) <[email protected]> wrote: > On Mon, Jan 24, 2011 at 3:41 PM, Mike Smith <[email protected]> wrote: >> I found this article about fixing duplicate errors, I know where to find the >> rids for the client. But on the server I do not see how or what I need to >> do with this article, do I delete all files in the queue dir? >> >> Thanks, >> >> Mike >> > > You should be able to delete the /var/ossec/queue/rids/*AGENT#* file. > *AGENT#* being the agent's ID number. > You'll probably have to restart the manager's ossec processes after > deleting the file. > >> On Mon, Jan 24, 2011 at 1:28 PM, Mike Smith <[email protected]> wrote: >>> >>> Is this happening to all agents or just some? >>> >>> Just 1 out of 10 >>> Were the agents that cannot connect now ever able to connect (maybe >>> before the upgrade)? >>> >>> Yes, it was working great >>> Which versions were they previously running? >>> >>> 2.4.1 >>> What platforms are the not working agents on (OS/revision)? >>> >>> Windows Server 2003 R2 >>> Are there any useful log messages on the OSSEC manager? >>> >>> 2011/01/24 09:02:29 ossec-remoted(1407): ERROR: Duplicated counter for >>> 'Server5'. >>> 2011/01/24 09:02:34 ossec-remoted: WARN: Duplicate error: global: 0, >>> local: 50, saved global: 38, saved local:8532 >>> 2011/01/24 09:02:34 ossec-remoted(1407): ERROR: Duplicated counter for >>> 'Server5'. >>> 2011/01/24 09:27:32 ossec-testrule: INFO: Reading local decoder file. >>> 2011/01/24 09:27:32 ossec-execd(1350): INFO: Active response disabled. >>> Exiting. >>> 2011/01/24 09:46:04 ossec-remoted(1403): ERROR: Incorrectly formated >>> message from '192.168.1.5'. >>> 2011/01/24 09:47:14 ossec-remoted(2202): ERROR: Error uncompressing >>> string. >>> >>> Thanks for your help, >>> >>> Mike >>> On Mon, Jan 24, 2011 at 12:35 PM, dan (ddp) <[email protected]> wrote: >>>> >>>> Hi Mike, >>>> >>>> On Mon, Jan 24, 2011 at 1:42 PM, Mike Smith <[email protected]> wrote: >>>> > Hello, >>>> > >>>> > I upgraded to 2.5.1 server and agents. Now I'm getting this warning. I >>>> > have >>>> > no Firewalls between server and agents. I uninstalled agent, did not >>>> > work, >>>> > i deleted agent from server, created new agent, still not working. >>>> > >>>> >>>> Is this happening to all agents or just some? >>>> Were the agents that cannot connect now ever able to connect (maybe >>>> before the upgrade)? >>>> Which versions were they previously running? >>>> What platforms are the not working agents on (OS/revision)? >>>> Are there any useful log messages on the OSSEC manager? >>>> >>>> >>>> > error message: >>>> > >>>> > 2011/01/24 11:02:39 ossec-agent: WARN: Process locked. Waiting for >>>> > permission... >>>> > 2011/01/24 11:02:50 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:02:52 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:03:13 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:03:33 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:03:54 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:04:32 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:04:53 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:05:49 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:06:10 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:07:24 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:07:45 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:09:17 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:09:38 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:11:28 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:11:49 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:13:57 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:14:18 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:16:44 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:17:05 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:19:49 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:20:10 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:23:12 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:23:33 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:26:53 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:27:14 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:30:52 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:31:13 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > 2011/01/24 11:35:09 ossec-agent: INFO: Trying to connect to server >>>> > (192.168.1.51:1514). >>>> > 2011/01/24 11:35:30 ossec-agent(4101): WARN: Waiting for server reply >>>> > (not >>>> > started). Tried: '192.168.1.51'. >>>> > >>>> > Thanks, >>>> > >>>> > -Mike >>> >> >> >
