2019/05/09 11:46:14 ossec-analysisd: ERROR: Could not write PID file '/var/run/ossec-analysisd-7399.pid': No space left on device (28) 2019/05/09 11:46:14 ossec-analysisd: CRITICAL: (1212): Unable to create PID file. 2019/05/09 11:46:28 ossec-syscheckd: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'. 2019/05/09 11:46:28 rootcheck: CRITICAL: (1211): Unable to access queue: '/var/ossec/queue/ossec/queue'. Giving up.. 2019/05/09 11:46:28 ossec-logcollector: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'. 2019/05/09 11:46:29 ossec-logcollector: CRITICAL: (1211): Unable to access queue: '/var/ossec/queue/ossec/queue'. Giving up.. 2019/05/09 11:46:29 wazuh-modulesd: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'. 2019/05/09 11:46:29 wazuh-modulesd: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'. 2019/05/09 11:47:17 sca: ERROR: Can't connect to queue. 2019/05/09 11:47:17 wazuh-modulesd: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'. 2019/05/09 11:47:17 wazuh-modulesd:syscollector: ERROR: Can't connect to queue. 2019/05/09 11:47:21 wazuh-modulesd: ERROR: At wm_sendmsg(): Unable to send message to queue: (No such file or directory) 2019/05/09 11:47:21 sca: ERROR: (1210): Queue '/queue/ossec/queue' not accessible: 'No such file or directory'.
du -bsh /folder
ps aux | grep ossec
lsof /var/ossec/logs/alerts/alerts.json
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
ossec-ana 2346 ossec 9w REG 8,1 288241 1836217 /var/ossec/logs/alerts/alerts.json
filebeat 2629 root 5r REG 8,1 288241 1836217 /var/ossec/logs/alerts/alerts.json
filebeat test output
logstash: IP:5000...
connection...
parse host... OK
dns lookup... OK
addresses: IP
dial up... OK
TLS... WARN secure connection disabled
talk to server... OK
/var/log/logstash/logstash-plain.log
[2019-04-16T07:54:49,457][INFO ][logstash.inputs.beats ] Beats inputs: Starting input listener {:address=>"0.0.0.0:5000"}
[2019-04-16T07:54:49,521][INFO ][logstash.pipeline ] Pipeline started successfully {:pipeline_id=>"main", :thread=>"#<Thread:0x785bc2c1 run>"}
[2019-04-16T07:54:49,659][INFO ][logstash.agent ] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[2019-04-16T07:54:49,713][INFO ][org.logstash.beats.Server] Starting server on port: 5000
[2019-04-16T07:54:50,213][INFO ][logstash.agent ] Successfully started Logstash API endpoint {:port=>9600}
curl IP_Elasticsearch:9200/_cluster/health?pretty
{
"cluster_name" : "my-cluster",
"status" : "green",
"timed_out" : false,
"number_of_nodes" : 1,
"number_of_data_nodes" : 1,
"active_primary_shards" : 21,
"active_shards" : 21,
"relocating_shards" : 0,
"initializing_shards" : 0,
"unassigned_shards" : 0,
"delayed_unassigned_shards" : 0,
"number_of_pending_tasks" : 0,
"number_of_in_flight_fetch" : 0,
"task_max_waiting_in_queue_millis" : 0,
"active_shards_percent_as_number" : 100.0
curl IP_Elasticsearch:9200/_cat/indices green open wazuh-monitoring-3.x-2019.03.22 iIV07lTrR_GaGS0JsILGEA 2 0 6 0 35kb 35kb green open .wazuh-version ZItpZuyaRr-1sW7ZAGL0Xg 1 0 1 0 5.1kb 5.1kb green open wazuh-monitoring-3.x-2019.04.16 PUWkHBk6Sw2snPk7NL8Iug 2 0 28 0 150kb 150kb green open .kibana_1 A4SoA1C2QUWXWm2rBL8TjQ 1 0 2 0 13.1kb 13.1kb green open palo-alto-2019.03.21 OXeGs99FR3CeTAG1AgEe1g 1 0 5115 0 755.1kb 755.1kb green open palo-alto-2019.03.22 lWhB_r1YR0CbI5_LQlvDYQ 1 0 9020 0 1.2mb 1.2mb green open wazuh-monitoring-3.x-2019.03.21 bZ2rqN2FSTOHqtD9YDKklQ 2 0 0 0 522b 522b green open .kibana_3 BO664i0LRhuu_bNl0NwyVQ 1 0 6 1 85kb 85kb green open .kibana_2 Fs2NPw55QRK5FyxE0QdCfQ 1 0 6 0 55.2kb 55.2kb green open wazuh-alerts-3.x-2019.04.16 1vxEQpnWT6ePhvXtjgzXRA 1 0 286 0 469kb 469kb green open wazuh-monitoring-3.x-2019.04.05 ldcOzaS7R0WsDcjvZtWn7A 2 0 14 0 73.8kb 73.8kb green open wazuh-alerts-3.x-2019.03.22 4Qp4t8vSS9eDTlc_N6zPjQ 1 0 3917 0 940.3kb 940.3kb green open .tasks zm93XMt6ST-h64PH2s_fIQ 1 0 1 0 6.2kb 6.2kb green open wazuh-alerts-3.x-2019.03.21 daTjtDX4RS2dwYgi2yGeLw 1 0 5571 0 1mb 1mb green open wazuh-alerts-3.x-2019.04.05 p3HZyYnfQCqTeudOV_gmBA 1 0 79 0 156.1kb 156.1kb green open .wazuh VIhi_jdySrqwXDn42gFobQ 1 0 2 0 21.6kb 21.6kb green open wazuh-alerts-3.x-2019.04.04 f0UtQ8O0S465U7YUF-HoLA 1 0 508 0 430.7kb 430.7kb
/var/log/elasticsearch/
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/812c41b6-e75d-475d-8189-6715c377632c%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/9297e61e-531d-4166-874b-61051cea032b%40googlegroups.com.
PUT */_settings
{
"index.blocks.read_only_allow_delete": null
}
systemctl restart kibana/etc/elasticsearch/elasticsearch.yml--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/92f45efe-73c6-4129-8e5b-af25038fbf3d%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/14ad9650-381b-452a-8ba4-49bf178f4ce0%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.