>To help anyone else who may be having similar issues, what was the solution?
I did everything at once so I wasn't able to diagnose exactly what caused it. I think what you mentioned played a role - duplicate <localfile> tags in my agent.conf file. Instead of having ossec.conf being configured for both secure and syslog for the <remote> tag, I chose the secure. I then went into each ossec.conf file on agents and under the <client> tag I used the <port> tag as well to ensure that agents were only communicating through one port. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/groups/opt_out.
