Looking at the source for 2.4, local_ip is there. I have no idea why OSSEC would choose an unrelated IP address instead of the one defined in <local_ip>.
What's the `ifconfig -a` for this server? The <remote> section in the manager's ossec.conf? On Thu, Apr 12, 2012 at 1:10 PM, Alisha Kloc <[email protected]> wrote: > All right, so I tried using the local_ip option - but no luck. > > Netstat -uan reports that the box is listening on eth0 to the OSSEC > port. However, OSSEC still didn't pick up any agent messages. I turned > eth3 down, and immediately got agent messages. Turned it back up, > messages stopped. > > So local_ip has no effect on this problem. The OSSEC Manager wants to > listen to eth3 unless forced to do otherwise. > > I've got no idea what to try next... any suggestions?
