<directories check_all="yes" whodata="yes">D:</directories>2019/03/15 10:03:22 ossec-agent: ERROR: It was not possible to extract the permissions of 'AFILEYOUARETRYINGTOMONITOR'. Error: -3.
Hi Daniel.Thanks again for your support. I've found the problem by myself: windows logs was full and wasn't deleted automatically.Anyway i've another problem, another agent start the monitoring check for a couple of hour then stop working.attach to this mail you can find logs and configuration.Thank again.
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/xw50uEh8oQo/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d586f5cb-973f-452e-b8ca-34238d5896fe%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d586f5cb-973f-452e-b8ca-34238d5896fe%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/xw50uEh8oQo/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/3bb262f4-5591-4e65-87d4-a75578600f72%40googlegroups.com.
/var/ossec/log/alerts/alerts.log/var/ossec/log/alerts/alerts.json
Hi Daniel.I hope to bore you for the last time.i've setted up a path to folder and no to disk for whodata logging, all works fine until 1:30 pm, when logs stopped to appear in console.Event viewer on the machine still generate log, wazuh is up and running, but no log on console. attached to this mail you can find ossec configuration and console.
Have a nice day.Il giorno lun 18 mar 2019 alle ore 14:48 Stefano Serano <serano...@gmail.com> ha scritto:Hi Daniel.I hope to bore you for the last time.i've setted up a path to folder and no to disk for whodata logging, all works fine until 1:30 pm, when logs stopped to appear in console.Event viewer on the machine still generate log, wazuh is up and running, but no log on cosole. attached to this mail you can find ossec configuration and console.Have a nice day.
To unsubscribe from this group and all its topics, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d586f5cb-973f-452e-b8ca-34238d5896fe%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/xw50uEh8oQo/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+unsubscribe@googlegroups.com.
2019/03/15 10:31:30 ossec-agent: ERROR: It was not possible to extract the permissions of 'PATH'. Error: -3.
I can see more than 10000 lines with that kind of error. I think you don't have permissions in the entire directory tree.Hi Daniel.I'm receiving Logs from Agent, but not the logs about files added/delete/modified.I make an example:I Can see in Windows Event Viewer(Server windows 2008 R2) a lot of events 4663(i checked few minutess ago, 10:15 AM), but on wazuh i have no alert, last was at 9.28 AM about a file added to the system.Even into:/var/ossec/log/alerts/alerts.log/var/ossec/log/alerts/alerts.jsoni can't see other logs about files added, deleted, modified.On the system is installed Kaspesky Security 10(just in case you need to know).Let me know if i can do something to figured it out.Have a nice Day.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ad14d90c-a2b4-48e8-a560-8d56607c2fe2%40googlegroups.com.
Hi Daniel.I've probably figured out. Our IT Costumed added a lot of path to be monitored, one of them had ad "à" font inside the pat, this cause the crash of whodata for all the path.I'll let you know if is really solved in the next days.Have a nice day.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/a6a0ec7e-4877-4b26-a9eb-f7c0770319cd%40googlegroups.com.
Hi Daniel.All work fine now, but i have a last questton for you.I've enabled integrity monitor with who-data on a windows server 2008 r3 and I've enabled local audit policy.I've noticed that when i delete a file, into the log on Kibana i can't see who deleted that file. is that right or i missing something into the configuration?Have a nice day.
Il giorno mar 26 mar 2019 alle ore 16:44 Stefano Serano <serano...@gmail.com> ha scritto:
Hi Daniel.I think problem is solved after removed that specific directory.Wazuh logs show me permission error even if i start the service with Domain Admin user account. I checked the permission on some of those files and i can confirm that are accessible from the wazuh service user account. Anyway even with those errors now i can see logs in console, i'll monitor the situation for another few days and give you a feedback soon.Have a nice day.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/780f83e6-9c0e-4ec2-a059-400e32326040%40googlegroups.com.
Ok Daniel i've solved, i was sure i've configured whodata but was realtime instead.A question about this:You said to set up "Security Settings -> Local Policies -> Audit Policy -> Audit object access" ONLY if i had Vista or Server 2008 O.S.. Do you mean even Server 2008 R2? because can be a little bit tricky for us.Have a nice day
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/776acec7-9238-4e46-a27d-55b0c02ffa9b%40googlegroups.com.
Many thanks Daniel for your support and patient.i've two new question for you:1- i've enabled whodata on a windows server 2008 R2 where it monitor a 1.2 TB shared disk. after the first syscheck scan was completed and realtime engine started this error appear and the service go down:2019/03/28 06:57:55 ossec-agent: CRITICAL: (1102): Could not acquire memory due to [(12)-(Visual C++ CRT: Not enough memory to complete call to strerror.)].
2019/03/28 06:57:55 ossec-agent: INFO: (1314): Shutdown received. Deleting responses.
Maybe not enough ram? the server has 12 GB but maybe to maintain active the real time on a 1.2 TB disk it need more boost?
2- a syscheck scan on this disk take 2 day to complete, this mean than for 2 day i'm unable to recieve whodata info. thhere is a way to disable syscheck scan after the first run? or at least a way to keep realtime engine up during the scan?
Have a nice day.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/38eccffa-8d52-4f53-a704-e1ac9d845c0f%40googlegroups.com.