What were the permissions on the shared directory? Is the shared directory empty? If the files are being deleted out of that directory, you'll have to find out why. Maybe try stopping the agent, manually copying the shared files over to it and starting it back up.
On Sun, Feb 13, 2011 at 1:48 AM, tayebe <[email protected]> wrote: > yes. it's only about 1 windows agent. my linux agent works very well. > "merged.mg " in this agent transfers rapidly, but it disappears very > quickly. restarting agent and server could'nt help. i checked > permission on windows side too. i shared shared folder without > permission, but there is not any progress. > > > On Feb 8, 5:40 pm, "dan (ddp)" <[email protected]> wrote: >> On Tue, Feb 8, 2011 at 1:12 AM, tayebeh amiri <[email protected]> wrote: >> > hi dan. >> > yes,i have that command. >> > my problem is ar.conf does'nt exist on my shared directory on agent .when i >> > manually create it,this test works well.but if i changed config of the >> > server,ar.conf does'nt update.not ar.conf,but also all files in shared >> > directory do'nt update.such as win_audit_rcl. >> > here is my agent config: >> >> Check the permissions on the files in /var/ossec/etc/shared, as well >> as the shared directory on the Windows side. >> Is this only an issue with 1 agent? >> >> > <!-- OSSEC Win32 Agent Configuration. >> > - This file is compost of 3 main sections: >> > - - Client config - Settings to connect to the OSSEC server. >> > - - Localfile - Files/Event logs to monitor. >> > - - syscheck - System file/Registry entries to monitor. >> > --> >> >> > <!-- READ ME FIRST. If you are configuring OSSEC for the first time, >> > - try to use the "Manage_Agent" tool. Go to control panel->OSSEC Agent >> > - to execute it. >> > - >> > - First, add a server-ip entry with the real IP of your server. >> > - Second, and optionally, change the settings of the files you want >> > - to monitor. Look at our Manual and FAQ for more information. >> > - Third, start the Agent and enjoy. >> > - >> > - Example of server-ip: >> > - <client> <server-ip>1.2.3.4</server-ip> </client> >> > --> >> >> > <ossec_config> >> >> > <!-- One entry for each file/Event log to monitor. --> >> > <localfile> >> > <location>Application</location> >> > <log_format>eventlog</log_format> >> > </localfile> >> >> > <localfile> >> > <location>Security</location> >> > <log_format>eventlog</log_format> >> > </localfile> >> >> > <localfile> >> > <location>System</location> >> > <log_format>eventlog</log_format> >> > </localfile> >> >> > <!-- Rootcheck - Policy monitor config --> >> > <rootcheck> >> > <windows_audit>./shared/win_audit_rcl.txt</windows_audit> >> > <windows_apps>./shared/win_applications_rcl.txt</windows_apps> >> > <windows_malware>./shared/win_malware_rcl.txt</windows_malware> >> > </rootcheck> >> >> > <!-- Syscheck - Integrity Checking config. --> >> > <syscheck> >> >> > <!-- Default frequency, every 20 hours. It doesn't need to be higher >> > - on most systems and one a day should be enough. >> > --> >> > <frequency>72000</frequency> >> >> > <!-- By default it is disabled. In the Install you must choose >> > - to enable it. >> > --> >> > <disabled>no</disabled> >> >> > <!-- Default files to be monitored - system32 only. --> >> > <directories check_all="yes">%WINDIR%/win.ini</directories> >> > <directories check_all="yes">%WINDIR%/system.ini</directories> >> > <directories check_all="yes">C:\autoexec.bat</directories> >> > <directories check_all="yes">C:\config.sys</directories> >> > <directories check_all="yes">C:\boot.ini</directories> >> > <directories check_all="yes">%WINDIR%/System32/CONFIG.NT</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/AUTOEXEC.NT</directories> >> > <directories check_all="yes">%WINDIR%/System32/at.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/attrib.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/cacls.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/debug.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/drwatson.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/drwtsn32.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/edlin.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/eventcreate.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/eventtriggers.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/ftp.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/net.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/net1.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/netsh.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/rcp.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/reg.exe</directories> >> > <directories check_all="yes">%WINDIR%/regedit.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/regedt32.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/regsvr32.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/rexec.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/rsh.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/runas.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/sc.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/subst.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/telnet.exe</directories> >> > <directories check_all="yes">%WINDIR%/System32/tftp.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/tlntsvr.exe</directories> >> > <directories >> > check_all="yes">%WINDIR%/System32/drivers/etc</directories> >> > <directories check_all="yes">C:\Documents and Settings/All Users/Start >> > Menu/Programs/Startup</directories> >> > <ignore >> > type="sregex">.log$|.htm$|.jpg$|.png$|.chm$|.pnf$|.evtx$</ignore> >> >> > <!-- Windows registry entries to monitor. --> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\batfile</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\cmdfile</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\comfile</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\exefile</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\piffile</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Directory</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Folder</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Classes\Protocols</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Policies</windows_registry> >> > <windows_registry>HKEY_LOCAL_MACHINE\Security</windows_registry> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Internet >> > Explorer</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session >> > Manager\KnownDLLs</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies</windows_registry> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows >> > NT\CurrentVersion\Windows</windows_registry> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows >> > NT\CurrentVersion\Winlogon</windows_registry> >> >> > <windows_registry>HKEY_LOCAL_MACHINE\Software\Microsoft\Active >> > Setup\Installed Components</windows_registry> >> >> > <!-- Windows registry entries to ignore. --> >> >> > <registry_ignore>HKEY_LOCAL_MACHINE\Security\Policy\Secrets</registry_ignore> >> >> > <registry_ignore>HKEY_LOCAL_MACHINE\Security\SAM\Domains\Account\Users</registry_ignore> >> > <registry_ignore type="sregex">\Enum$</registry_ignore> >> > </syscheck> >> >> > <active-response> >> > <disabled>no</disabled> >> > </active-response> >> >> > </ossec_config> >> >> > <!-- END of Default Configuration. --> >> >> > <ossec_config> >> > <client> >> > <server-ip>192.168.1.20</server-ip> >> > </client> >> > </ossec_config> >> >> > On Mon, Feb 7, 2011 at 6:05 PM, dan (ddp) <[email protected]> wrote: >> >> >> Do you have a command named win_nullroute600? Please show us your config. >> >> Also make sure AR is enabled on the Windows agent. >> >> >> On Sun, Feb 6, 2011 at 2:32 AM, tayebe <[email protected]> wrote: >> >> > hello daniel. >> >> > I install ossec_hids 2.4.1 on a fedora core 13 as server,and on a >> >> > windows xp and a fc13 as agents.but unfortunatelly my windows agent >> >> > can't create ar.conf and merged.mg ,but my linux agent works >> >> > properly.when i use /var/ossec/bin/agent_control -b 1.2.1.2 -f >> >> > win_nullroute600 -u 017 for test ,i recieve error maessage in windows >> >> > agent logs: >> >> > ERROR: Unable to open file 'shared/ar.conf'. >> >> >> > ossec-execd(1311): ERROR: Invalid command name 'win_nullroute600' >> >> > provided. >> >> >> > i checked firewall in both server and agent also. >> >> > i do'nt know what to do.plz help me. >> >> > thx before.
