I Agree.

I guess will keep looking

thanks

On Feb 17, 2:13 pm, Jeremy Lee <[email protected]> wrote:
> Re-installing the OSSEC agent likely isn't going to resolve the issue. The
> issue is with something else on your box not related to OSSEC. OSSEC is just
> reporting/alerting on it.
>
>
>
>
>
>
>
> On Thu, Feb 17, 2011 at 9:09 AM, OSSEC <[email protected]> wrote:
> > FYI, I've just reinstalled the agent and still giving me the same
> > problem.
>
> > On Feb 17, 10:48 am, OSSEC <[email protected]> wrote:
> > > thanks all.
>
> > > Yeah i really want to find out what is going on, since i dont want to
> > > take the risk of just ignore it.
>
> > > This a Red Hat 5.X
>
> > > [root@BAI-MW2 bin]# uname -a
> > > Linux  2.6.18-194.17.4.el5 #1 SMP Wed Oct 20 13:03:08 EDT 2010 x86_64
> > > x86_64 x86_64 GNU/Linux
>
> > > That said im going to keep looking .. although i'm running out of
> > > ideas of where to look. If you have any ideas on how to troubleshoot
> > > more deeply please advice.
>
> > > Thanks again.
>
> > > On Feb 16, 6:00 pm, "Castle, Shane" <[email protected]> wrote:
>
> > > > I must say I have to agree with the research suggestion. One of my
> > systems had a failed opcode message that I probably would not have seen (or
> > noted the frequency) had it not been for the OSSEC install; turned out there
> > was an incorrect BIOS setting behind that.
>
> > > > This tendency of programs and syslog messages not to include a program
> > source identification is still with us, it seems. And, just saying that it's
> > "Linux" is not really enough info: Which distro? Release? Is it up to date?
>
> > > > --
> > > > Shane Castle
> > > > Data Security Mgr, Boulder County IT
> > > > CISSP GSEC GCIH
>
> > > > -----Original Message-----
> > > > From: [email protected] [mailto:[email protected]]
> > On Behalf Of Jeremy Lee
> > > > Sent: Wednesday, February 16, 2011 15:48
> > > > To: [email protected]
> > > > Subject: Re: [ossec-list] Re: alert level 2 error
>
> > > > Hmm... I'm not sure what that's from then.
>
> > > > If you want to ignore, you can simply add a rule to local_rules.xml.
> > Something like this:
>
> > > > <rule id="400001" level="0">
> > > >    <match>error initializing: -1</match>
> > > >    <description>Ignore "error initializing: -1" messages</description>
> > > >  </rule>
>
> > > > The risk is that this rule will ignore anything matching that "error
> > initializing: -1" keyword.
>
> > > > I would still try to find out where that error is coming from though,
> > just for the sake of due diligence.
>
> > > > On Wed, Feb 16, 2011 at 1:59 PM, OSSEC <[email protected]>
> > wrote:
>
> > > >         ok, i saw messages in other servers like this
>
> > > >         Feb 16 07:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 08:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 09:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 10:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 11:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 12:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 13:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 14:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 15:52:42 bai2-ibm-db1 : error initializing: -1
> > > >         Feb 16 16:52:42 bai2-ibm-db1 : error initializing: -1
>
> > > >         exactly every hour. So the DHCP looks irrelevant to the errors.
>
> > > >         It could be an IBM thing? but why just starting happening now?
>
> > > >         if i want to ignore it ... it will be a risk involved? if so
> > how i can
> > > >         ignore the alert
>
> > > >         On Feb 16, 4:28 pm, Jeremy Lee <[email protected]> wrote:
> > > >         > Looks like it's an issue with DHCP. Did you try Google to
> > look for help on
> > > >         > why DHCP might be acting up? Do you have multiple ethernet
> > adapters on this
> > > >         > server?
>
> > > >         > If you're certain these errors aren't symptoms of a larger
> > problem, you
> > > >         > could always setup a rule to ignore them.
>
> > > >         > On Wed, Feb 16, 2011 at 1:18 PM, OSSEC <
> > [email protected]> wrote:
> > > >         > > Here is in another server
>
> > > >         > > Feb 16 15:31:43 BAI-MW1 dhclient: bound to 169.254.95.120
> > -- renewal
> > > >         > > in 301 seconds.
> > > >         > > Feb 16 15:35:43 BAI-MW1 : error initializing: -1
> > > >         > > Feb 16 15:36:44 BAI-MW1 dhclient: DHCPREQUEST on usb0 to
> > > >         > > 169.254.95.118 port 67
> > > >         > > Feb 16 15:36:44 BAI-MW1 dhclient: DHCPACK from
> > 169.254.95.118
>
> > > >         > > These servers are used for weblogic
>
> > > >         > > On the other two servers the date is wrong ...  will fix
> > that soon,
> > > >         > > but im not sure if that was causing the issue. (these are
> > test
> > > >         > > servers)
>
> > > >         > > On Feb 16, 3:58 pm, "dan (ddp)" <[email protected]> wrote:
> > > >         > > > Look at the proceeding lines, maybe there is a clue
> > there. What's the
> > > >         > > > purpose of this system?
>
> > > >         > > > On Wed, Feb 16, 2011 at 3:36 PM, OSSEC <
> > [email protected]> wrote:
> > > >         > > > > Im using linux
>
> > > >         > > > > Here is what i found in /var/log/messages
>
> > > >         > > > > Feb 16 15:15:33 BAI-DB2 : error initializing: -1
>
> > > >         > > > > tons of those lines
>
> > > >         > > > > On Feb 16, 3:20 pm, Jeremy Lee <[email protected]>
> > wrote:
> > > >         > > > >> If in Windows just open the log with Notepad, Wordpad,
> > etc and run a
> > > >         > > "Find"
>
> > > >         > > > >> You should be able to identify the log source that
> > this came from, as
> > > >         > > Dan
> > > >         > > > >> has pointed out.
>
> > > >         > > > >> Let us know.
>
> > > >         > > > >> On Wed, Feb 16, 2011 at 12:12 PM, dan (ddp) <
> > [email protected]> wrote:
> > > >         > > > >> > As can be seen here:
>
> >http://www.ossec.net/wiki/Know_How:Email_Alerts_below_7
> > > >         > > > >> > the name of the logfile is generally in the alert
> > ("Received From:
> > > >         > > > >> > (foo) 192.168.0.2->/var/log/messages").
> > > >         > > > >> > If it isn't in your alert message, you can use grep
> > if you're on a
> > > >         > > > >> > sane(r) system. I'm not sure how to find it with
> > Windows.
>
> > > >         > > > >> > On Wed, Feb 16, 2011 at 3:06 PM, OSSEC <
> > [email protected]>
> > > >         > > wrote:
> > > >         > > > >> > > Hey Dan,
>
> > > >         > > > >> > > bai-mw1 is the name of the agent. How i can find
> > out the log that
> > > >         > > > >> > > message is hidden?
>
> > > >         > > > >> > > thanks
>
> > > >         > > > >> > > On Feb 16, 2:50 pm, "dan (ddp)" <[email protected]>
> > wrote:
> > > >         > > > >> > >> Hi Chris,
> > > >         > > > >> > >> Find out what BAI-MW1 is. Knowing which log that
> > message is
> > > >         > > hidden in
> > > >         > > > >> > >> might be useful.
> > > >         > > > >> > >> Then write a rule for the log message.
>
> > > >         > > > >> > >> On Wed, Feb 16, 2011 at 2:46 PM, OSSEC <
> > [email protected]
>
> > > >         > > > >> > wrote:
> > > >         > > > >> > >> > Greetings,
>
> > > >         > > > >> > >> > all of the sudden i've started receiving the
> > following error
> > > >         > > message
>
> > > >         > > > >> > >> > "Unknown problem somewhere in the system."
> > > >         > > > >> > >> > Portion of the log(s):
>
> > > >         > > > >> > >> > Feb 16 14:35:43 BAI-MW1 : error initializing:
> > -1
>
> > > >         > > > >> > >> > I;ve restarted the agents and servers but i
> > still having the
> > > >         > > same
> > > >         > > > >> > >> > issue. These alerts are coming out of few
> > agents not all of
> > > >         > > them.
>
> > > >         > > > >> > >> > ANy ideas please?
>
> > > >         > > > >> > >> > thanks

Reply via email to