On Thu, Mar 13, 2014 at 1:53 PM, Mike Wisniewski <[email protected]> wrote:
> Simple question...  Do I have to install an OSSEC agent on the Server?  If
> so, should I specify a different default directory?
>

No, you do not need to install an OSSEC agent on the OSSEC manager.
The server installation performs those functions for that system
already.

> Something makes me think I don't think so because the server already
> monitors files, but I'm seeing this message...
>
> 2014/03/13 12:42:17 ossec-analysisd(1210): ERROR: Queue '/queue/alerts/ar'
> not accessible: 'Connection refused'.
> 2014/03/13 12:42:17 ossec-analysisd(1301): ERROR: Unable to connect to
> active response queue.
> 2014/03/13 12:42:17 ossec-analysisd: INFO: Connected to
> '/queue/alerts/execq' (exec queue)
>

Are you using active response?

> and the FAQ says to install the agent....but it's a server that's already
> being monitored by OSSEC by default.
>

I'll have to check that out, because it makes no sense.

> Thanks in advanced.
>
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to