On Tue, Jul 10, 2012 at 3:10 AM, OK <[email protected]> wrote: > I know this thread is over a year silent now. I have discovered the same > error message, also on an agent and also with centralized configuration. > The messages only show up on my Solaris agent. I have configured to > automatically restart OSSEC if the agent.conf changes. Since the manager is > running on CentOS and notified in realtime, that the agent.conf changed, I > get an immediate restart of OSSEC on the manger. The new agent.conf will be > pushed then directly to the clients, what causes the other CentOS with > realtime monitoring to restart OSSEC. Since on Solaris > the realtime monitoring is not working, I need two syscheck cycles to ralize > there is a new agent.conf file and OSSEC restarts. The messages occur in the > period between the managers restart and the Solaris agent restart on the > Solaris agent. They will disappear after a successful restart of the Solaris > agent. > This is what I have seen in my environment, I have no idea if that is the > correct behavior of OSSEC in that case or not. I have also not checked if I > can force the agent to restart if he receives this Messages. > >
Which error messages are you getting exactly? What does your AR configuration look like? What AR scripts do you have available on the agents? Are the permissions correct? When you run agentd/execd in debug mode, do any new error messages appear?
