This is because manage_agent also uses a chroot environment, changing root
directory to OSSEC home (/var/ossec)
Try running the command with strace and you will see something like this:
...
setgid(1003) = 0
chdir("/var/ossec") = 0
chroot("/var/ossec") = 0
chdir("/") = 0
...
open("/var/ossec/tmp/test", O_RDONLY) = -1 ENOENT (No such file or
directory)
...
On Sat, Feb 20, 2016 at 7:44 PM, Barry Kaplan <[email protected]> wrote:
> Ok, I guess I just figured it out. The bulk file needs to be a relative
> directory
>
> $ /var/ossec/bin/manage_agents -f tmp/agent-ops-control-1
> Bulk load file: tmp/agent-ops-control-1
> Opening: [tmp/agent-ops-control-1]
> Agent information:
> ID:005
> Name:ops-control-1
> IP Address:10.0.196.133
>
> Agent added.
>
> Why must this be?
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.
>
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.