Hi there, I am manually trying to run the ossec-reportd process to have a look at some of the reporting available, and I am getting the following error:
ossec-reportd(1207): ERROR: Unable to switch to group: 'ossec'.
I’m running the following for my initial test:
cat /var/ossec/logs/alerts/alerts.log | /var/ossec/ossec-reportd -n “Failures summary” -f group authentication_failures
The OS I’m using is Ubuntu server 10.04 LTS.
Hopefully someone has come across this and fixed it, fingers crossed J
Scott Closter
The ossec group exists right?
Scott Closter | | CU Technical & Administrative Services Corp. | 250
627 3654
Scott
Scott Closter