Hi Dan, 

in our Case the directory is /app/ossec (for example), so we are not using 
the default behavior. 

When installing in "compiling" mode, each directory for ossec will be 
installed in /app/ossec, also the queue example will be installed to : 
/app/ossec/queue/ossec/...
This is working fine. 

Binary Mode: 
above example compiled and packaded. added binary mode flag to 
preloaded-vars. install.sh

1. Normal directory will be setup correctly, so /app/ossec was created, but 
the internal logic for the queue is pointet to /queue... this is the 
default path i have found in src/headers/defs.h 

Same configs but different behavior :) 

best regards 

 

On Tuesday, December 9, 2014 4:56:49 PM UTC+1, dan (ddpbsd) wrote:
>
> On Tue, Dec 9, 2014 at 10:46 AM, Philipp Hoferichter <[email protected] 
> <javascript:>> wrote: 
> > Hi Dan, 
> > 
> > i want to package the compiled server to can install this on different 
> > locations. 
> > And therefore i need a working "binary" mode package, becasue i won´t 
> > compile the ossec server on each system. 
> > 
>
> Oh ok, that makes sense. 
>
> > With "normal" mode, the direcotry defined in the preloaded-vars and 
> LOCATION 
> > will be used for the queue. 
> > With "binary" mode, the default directory (example above) will be used, 
> but 
> > this is wrong, preload-vars are in both cases identical 
> > 
>
> I must be an idiot because this makes very little sense to me. 
> The correct directory is /var/ossec, right? 
> "/var/ossec" works when compiled on the system? 
> "/var/ossec" does not work when compiled on a different system and 
> installed using the binary installation method? 
>
>
>
> > best regards 
> > 
> > On Tuesday, December 9, 2014 1:45:06 PM UTC+1, dan (ddpbsd) wrote: 
> >> 
> >> On Tue, Dec 9, 2014 at 2:43 AM, Philipp Hoferichter <[email protected]> 
> wrote: 
> >> > yes group is available. 
> >> > 
> >> > The Installation is working on same server with "normal" mode, but in 
> >> > binary 
> >> > mode (after compiling) the wrong queue directory is used. 
> >> > 
> >> 
> >> I'm confused. if you installed it normally on the system, why are you 
> >> trying to install it via the binary method? 
> >> Also, what queue directory should it be using? 
> >> 
> >> > best regards 
> >> > 
> >> > 
> >> > On Monday, December 8, 2014 4:36:02 PM UTC+1, dan (ddpbsd) wrote: 
> >> >> 
> >> >> On Mon, Dec 8, 2014 at 10:30 AM, Philipp Hoferichter <[email protected]> 
>
> >> >> wrote: 
> >> >> > We have an error with installing the OSSEC Server when using 
> Binary 
> >> >> > Installation Mode: 
> >> >> > 
> >> >> > Example: 
> >> >> > 2014/12/08 16:26:46 Could not get ossec gid. 
> >> >> 
> >> >> Does the ossec group exist? 
> >> >> 
> >> >> > Started ossec-analysisd... 
> >> >> > 2014/12/08 16:26:46 ossec-logcollector(1103): ERROR: Unable to 
> open 
> >> >> > file 
> >> >> > '/queue/ossec/.agent_info'. 
> >> >> > Started ossec-logcollector... 
> >> >> > Started ossec-remoted... 
> >> >> > 2014/12/08 16:26:46 ossec-syscheckd(1103): ERROR: Unable to open 
> file 
> >> >> > '/queue/ossec/.agent_info'. 
> >> >> > 2014/12/08 16:26:46 ossec-syscheckd(1103): ERROR: Unable to open 
> file 
> >> >> > '/queue/ossec/.agent_info'. 
> >> >> > Started ossec-syscheckd... 
> >> >> > Started ossec-monitord... 
> >> >> > Completed. 
> >> >> > 
> >> >> > 
> >> >> > When we are using "compiling" mode, the queue will be created 
> >> >> > successfully. 
> >> >> > 
> >> >> > Maybe something to change in src/headers/defs.h ? 
> >> >> > 
> >> >> > best regards 
> >> >> > 
> >> >> > Philipp 
> >> >> > 
> >> >> > -- 
> >> >> > 
> >> >> > --- 
> >> >> > You received this message because you are subscribed to the Google 
> >> >> > Groups 
> >> >> > "ossec-list" group. 
> >> >> > To unsubscribe from this group and stop receiving emails from it, 
> >> >> > send 
> >> >> > an 
> >> >> > email to [email protected]. 
> >> >> > For more options, visit https://groups.google.com/d/optout. 
> >> > 
> >> > -- 
> >> > 
> >> > --- 
> >> > You received this message because you are subscribed to the Google 
> >> > Groups 
> >> > "ossec-list" group. 
> >> > To unsubscribe from this group and stop receiving emails from it, 
> send 
> >> > an 
> >> > email to [email protected]. 
> >> > For more options, visit https://groups.google.com/d/optout. 
> > 
> > -- 
> > 
> > --- 
> > You received this message because you are subscribed to the Google 
> Groups 
> > "ossec-list" group. 
> > To unsubscribe from this group and stop receiving emails from it, send 
> an 
> > email to [email protected] <javascript:>. 
> > For more options, visit https://groups.google.com/d/optout. 
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to