On Thu, Sep 29, 2016 at 10:03 AM, Eduardo Reichert Figueiredo <[email protected]> wrote: > Hi, > i have a serious problem with ossec. Windows 2012 r2 servers not comunicate > with ossec server. I am use ossec just integrity check, only! So i need > that my agent to send logs of syscheck for ossec server, only, but is not > ok. I viewed many foruns about this, but i dont found solution. > > - Client.keys OK > - Agent Windows send logs for OSSEC server OK > - OSSEC proccess running OK > > The ossec not created automatically file in /var/ossec/queue/syscheck > > Can someone help me? >
Enable debug on the OSSEC server: `/var/ossec/bin/ossec-control enable debug` Restart the OSSEC processes: `/var/ossec/bin/ossec-control restart` Check `/var/ossec/logs/ossec.log` for errors related to that agent. Check with tcpdump on the OSSEC server for packets from the agent. Do they come from the expected IP address? > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
