I stopped the ossec server. then I uninstalled the agent. Next I created a new agent, extracted key and reinstalled.
Then, it was working, until I added the real time monitoring. then it errored out, so I removed the real time monitoring, it was working again. So now my only issue with this client is the correct way to setup real time monitoring on a windows agent. Thanks for all of your help, -Mike On Mon, Jan 24, 2011 at 3:20 PM, dan (ddp) <[email protected]> wrote: > Mike, > You mentioned in the realtime thread that you got the agent working. > Did deleting the rids files fix this or was it something else? > Thanks > > On Mon, Jan 24, 2011 at 4:30 PM, dan (ddp) <[email protected]> wrote: > > On Mon, Jan 24, 2011 at 3:41 PM, Mike Smith <[email protected]> > wrote: > >> I found this article about fixing duplicate errors, I know where to find > the > >> rids for the client. But on the server I do not see how or what I need > to > >> do with this article, do I delete all files in the queue dir? > >> > >> Thanks, > >> > >> Mike > >> > > > > You should be able to delete the /var/ossec/queue/rids/*AGENT#* file. > > *AGENT#* being the agent's ID number. > > You'll probably have to restart the manager's ossec processes after > > deleting the file. > > > >> On Mon, Jan 24, 2011 at 1:28 PM, Mike Smith <[email protected]> > wrote: > >>> > >>> Is this happening to all agents or just some? > >>> > >>> Just 1 out of 10 > >>> Were the agents that cannot connect now ever able to connect (maybe > >>> before the upgrade)? > >>> > >>> Yes, it was working great > >>> Which versions were they previously running? > >>> > >>> 2.4.1 > >>> What platforms are the not working agents on (OS/revision)? > >>> > >>> Windows Server 2003 R2 > >>> Are there any useful log messages on the OSSEC manager? > >>> > >>> 2011/01/24 09:02:29 ossec-remoted(1407): ERROR: Duplicated counter for > >>> 'Server5'. > >>> 2011/01/24 09:02:34 ossec-remoted: WARN: Duplicate error: global: 0, > >>> local: 50, saved global: 38, saved local:8532 > >>> 2011/01/24 09:02:34 ossec-remoted(1407): ERROR: Duplicated counter for > >>> 'Server5'. > >>> 2011/01/24 09:27:32 ossec-testrule: INFO: Reading local decoder file. > >>> 2011/01/24 09:27:32 ossec-execd(1350): INFO: Active response disabled. > >>> Exiting. > >>> 2011/01/24 09:46:04 ossec-remoted(1403): ERROR: Incorrectly formated > >>> message from '192.168.1.5'. > >>> 2011/01/24 09:47:14 ossec-remoted(2202): ERROR: Error uncompressing > >>> string. > >>> > >>> Thanks for your help, > >>> > >>> Mike > >>> On Mon, Jan 24, 2011 at 12:35 PM, dan (ddp) <[email protected]> wrote: > >>>> > >>>> Hi Mike, > >>>> > >>>> On Mon, Jan 24, 2011 at 1:42 PM, Mike Smith <[email protected]> > wrote: > >>>> > Hello, > >>>> > > >>>> > I upgraded to 2.5.1 server and agents. Now I'm getting this > warning. I > >>>> > have > >>>> > no Firewalls between server and agents. I uninstalled agent, did > not > >>>> > work, > >>>> > i deleted agent from server, created new agent, still not working. > >>>> > > >>>> > >>>> Is this happening to all agents or just some? > >>>> Were the agents that cannot connect now ever able to connect (maybe > >>>> before the upgrade)? > >>>> Which versions were they previously running? > >>>> What platforms are the not working agents on (OS/revision)? > >>>> Are there any useful log messages on the OSSEC manager? > >>>> > >>>> > >>>> > error message: > >>>> > > >>>> > 2011/01/24 11:02:39 ossec-agent: WARN: Process locked. Waiting for > >>>> > permission... > >>>> > 2011/01/24 11:02:50 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:02:52 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:03:13 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:03:33 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:03:54 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:04:32 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:04:53 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:05:49 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:06:10 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:07:24 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:07:45 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:09:17 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:09:38 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:11:28 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:11:49 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:13:57 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:14:18 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:16:44 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:17:05 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:19:49 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:20:10 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:23:12 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:23:33 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:26:53 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:27:14 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:30:52 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:31:13 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > 2011/01/24 11:35:09 ossec-agent: INFO: Trying to connect to server > >>>> > (192.168.1.51:1514). > >>>> > 2011/01/24 11:35:30 ossec-agent(4101): WARN: Waiting for server > reply > >>>> > (not > >>>> > started). Tried: '192.168.1.51'. > >>>> > > >>>> > Thanks, > >>>> > > >>>> > -Mike > >>> > >> > >> > > >
