Hi, Can you help me?
When I run search in splunk,I get next message:
Server Hostname of my ossec-server, Error: Unable to run data collection.What
is
the meaning of that error and how to fix it?
(Splunk and Ossec are installed on the same server and curiously I get live
report in splunk when for example I login as root on ossec agent and I enter
wrong password or when I change the content of ossec.conf file on ossec server
or on ossec agent(ossec syscheck alert is sent into splunk)
Regards,
Nepo
