On Feb 28, 2014 4:33 PM, "OsO Roñoso" <[email protected]> wrote:
>
> Ok...
>
> root@lenga # /var/ossec/bin/ossec-logcollector -d
> 2014/02/28 18:14:17 ossec-logcollector: DEBUG: Starting ...
>
>
> root@lenga # tail -f ossec.log
> 2014/02/28 18:14:17 ossec-logcollector: DEBUG: Starting ...
> 2014/02/28 18:14:17 ossec-logcollector: DEBUG: Waiting main daemons to
settle.
> 2014/02/28 18:14:26 ossec-logcollector(1210): ERROR: Queue
'/var/ossec/queue/ossec/queue' not accessible: 'Destination address
required'.
> 2014/02/28 18:14:26 ossec-logcollector(1211): ERROR: Unable to access
queue: '/var/ossec/queue/ossec/queue'. Giving up..
>

Was ossec-agentd running when you did this? If not start it and try this
again. If that doesn't work, try chowning the .agent_info file below to
root. That seems familiar for some reason.

> root@lenga # ls -las
> total 4
>    2 drwxrwx---   2 ossec    ossec        512 Feb 28 13:03 .
>    2 dr-xr-x---   7 root     ossec        512 Feb 28 12:54 ..
>    0 -rw-r--r--   1 ossec    ossec          0 Feb 28 13:03 .agent_info
>    0 sr-xr-x---   1 root     ossec          0 Feb 28 13:03 queue
>
>
>
> El viernes, 28 de febrero de 2014 13:22:38 UTC-3, dan (ddpbsd) escribió:
>>
>> On Fri, Feb 28, 2014 at 11:19 AM, OsO Roñoso <[email protected]> wrote:
>> > root@lenga # /var/ossec/bin/ossec-agentd -df
>> > /var/ossec/bin/ossec-agentd: illegal option -- f
>>
>> I guess it's possible that wasn't avaialble for 2.7.1, I haven't used
>> that version for a while.
>>
>> > 2014/02/28 12:59:42 ossec-agentd: DEBUG: Starting ...
>> >
>> >
>> > root@lenga # tail -f ossec.log
>> > 2014/02/28 12:59:42 ossec-agentd: DEBUG: Starting ...
>> > 2014/02/28 12:59:42 ossec-agentd(1410): INFO: Reading authentication
keys
>> > file.
>> > 2014/02/28 12:59:42 ossec-agentd: OS_StartCounter: keysize: 1
>> >
>>
>> Ok, so no errors? It continued running fine?
>> If so, try running ossec-logcollector next:
>> `/var/ossec/bin/ossec-logcollector -d`
>> Keep checking ossec.log
>>
>>
>> > root@lenga # pwd
>> > /var/ossec/etc
>> > root@lenga # ls -las
>> > total 24
>> >    2 dr-xr-x---   3 root     ossec        512 Feb 28 12:58 .
>> >    2 dr-xr-x---  11 root     ossec        512 Feb 28 12:54 ..
>> >    2 -r--r-----   1 root     ossec         88 Feb 28 12:58 client.keys
>> >    6 -r--r-----   1 root     ossec       2842 Oct 29 15:13
>> > internal_options.conf
>> >    2 -rw-r-----   1 root     root         103 Feb 28 12:54
ossec-init.conf
>> >    6 -r--r-----   1 root     ossec       2430 Feb 28 12:53 ossec.conf
>> >    2 drwxrwx---   2 root     ossec        512 Feb 28 12:54 shared
>> >    2 -r-xr-xr-x   1 root     ossec        826 May 24  2011 TIMEZONE
>> >
>> >
>> >
>> > El viernes, 28 de febrero de 2014 13:04:35 UTC-3, dan (ddpbsd)
escribió:
>> >>
>> >> On Fri, Feb 28, 2014 at 11:00 AM, OsO Roñoso <[email protected]>
wrote:
>> >> >
>> >> > I can not even start the service, I've set a couple of times but
with
>> >> > the
>> >> > same result on 2 machines with solaris and this is the form i'm run
the
>> >> > commands  "./ossec-logcollector ../etc/ossec.conf -d -u ossec -g
ossec"
>> >>
>> >> Try just `/var/ossec/bin/ossec-agentd -df`
>> >> ossec-agentd appears to be the first one that should be started, and
>> >> it's the one giving you the errors.
>> >>
>> >> > when you say keyfile, you do refer "client.keys" file?
>> >> >
>> >>
>> >> Yes.
>> >
>> > --
>> >
>> > ---
>> > You received this message because you are subscribed to the Google
Groups
>> > "ossec-list" group.
>> > To unsubscribe from this group and stop receiving emails from it, send
an
>> > email to [email protected].
>> > For more options, visit https://groups.google.com/groups/opt_out.
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
"ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
email to [email protected].
> For more options, visit https://groups.google.com/groups/opt_out.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to