I stopped the ossec server.  then I uninstalled the agent.  Next I created a
new agent, extracted key and reinstalled.

Then, it was working, until I added the real time monitoring. then it
errored out, so I removed the real time monitoring, it was working again. So
now my only issue with this client is the correct way to setup real time
monitoring on a windows agent.

Thanks for all of your help,

-Mike

On Mon, Jan 24, 2011 at 3:20 PM, dan (ddp) <[email protected]> wrote:

> Mike,
> You mentioned in the realtime thread that you got the agent working.
> Did deleting the rids files fix this or was it something else?
> Thanks
>
> On Mon, Jan 24, 2011 at 4:30 PM, dan (ddp) <[email protected]> wrote:
> > On Mon, Jan 24, 2011 at 3:41 PM, Mike Smith <[email protected]>
> wrote:
> >> I found this article about fixing duplicate errors, I know where to find
> the
> >> rids for the client.  But on the server I do not see how or what I need
> to
> >> do with this article, do I delete all files in the queue dir?
> >>
> >> Thanks,
> >>
> >> Mike
> >>
> >
> > You should be able to delete the /var/ossec/queue/rids/*AGENT#* file.
> > *AGENT#* being the agent's ID number.
> > You'll probably have to restart the manager's ossec processes after
> > deleting the file.
> >
> >> On Mon, Jan 24, 2011 at 1:28 PM, Mike Smith <[email protected]>
> wrote:
> >>>
> >>> Is this happening to all agents or just some?
> >>>
> >>> Just 1 out of 10
> >>> Were the agents that cannot connect now ever able to connect (maybe
> >>> before the upgrade)?
> >>>
> >>> Yes, it was working great
> >>> Which versions were they previously running?
> >>>
> >>> 2.4.1
> >>> What platforms are the not working agents on (OS/revision)?
> >>>
> >>> Windows Server 2003 R2
> >>> Are there any useful log messages on the OSSEC manager?
> >>>
> >>> 2011/01/24 09:02:29 ossec-remoted(1407): ERROR: Duplicated counter for
> >>> 'Server5'.
> >>> 2011/01/24 09:02:34 ossec-remoted: WARN: Duplicate error:  global: 0,
> >>> local: 50, saved global: 38, saved local:8532
> >>> 2011/01/24 09:02:34 ossec-remoted(1407): ERROR: Duplicated counter for
> >>> 'Server5'.
> >>> 2011/01/24 09:27:32 ossec-testrule: INFO: Reading local decoder file.
> >>> 2011/01/24 09:27:32 ossec-execd(1350): INFO: Active response disabled.
> >>> Exiting.
> >>> 2011/01/24 09:46:04 ossec-remoted(1403): ERROR: Incorrectly formated
> >>> message from '192.168.1.5'.
> >>> 2011/01/24 09:47:14 ossec-remoted(2202): ERROR: Error uncompressing
> >>> string.
> >>>
> >>> Thanks for your help,
> >>>
> >>> Mike
> >>> On Mon, Jan 24, 2011 at 12:35 PM, dan (ddp) <[email protected]> wrote:
> >>>>
> >>>> Hi Mike,
> >>>>
> >>>> On Mon, Jan 24, 2011 at 1:42 PM, Mike Smith <[email protected]>
> wrote:
> >>>> > Hello,
> >>>> >
> >>>> > I upgraded to 2.5.1 server and agents. Now I'm getting this
> warning.  I
> >>>> > have
> >>>> > no Firewalls between server and agents.  I uninstalled agent, did
> not
> >>>> > work,
> >>>> > i deleted agent from server, created new agent, still not working.
> >>>> >
> >>>>
> >>>> Is this happening to all agents or just some?
> >>>> Were the agents that cannot connect now ever able to connect (maybe
> >>>> before the upgrade)?
> >>>> Which versions were they previously running?
> >>>> What platforms are the not working agents on (OS/revision)?
> >>>> Are there any useful log messages on the OSSEC manager?
> >>>>
> >>>>
> >>>> > error message:
> >>>> >
> >>>> > 2011/01/24 11:02:39 ossec-agent: WARN: Process locked. Waiting for
> >>>> > permission...
> >>>> > 2011/01/24 11:02:50 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:02:52 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:03:13 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:03:33 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:03:54 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:04:32 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:04:53 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:05:49 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:06:10 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:07:24 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:07:45 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:09:17 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:09:38 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:11:28 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:11:49 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:13:57 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:14:18 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:16:44 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:17:05 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:19:49 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:20:10 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:23:12 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:23:33 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:26:53 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:27:14 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:30:52 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:31:13 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> > 2011/01/24 11:35:09 ossec-agent: INFO: Trying to connect to server
> >>>> > (192.168.1.51:1514).
> >>>> > 2011/01/24 11:35:30 ossec-agent(4101): WARN: Waiting for server
> reply
> >>>> > (not
> >>>> > started). Tried: '192.168.1.51'.
> >>>> >
> >>>> > Thanks,
> >>>> >
> >>>> > -Mike
> >>>
> >>
> >>
> >
>

Reply via email to