cat /var/ossec/logs/ossec.log
2024/07/18 00:00:10 wazuh-monitord: INFO: Starting new log after rotation.
2024/07/18 00:17:49 sca: INFO: Starting Security Configuration Assessment scan.
2024/07/18 00:17:49 sca: INFO: Starting evaluation of policy: '/var/ossec/ruleset/sca/cis_centos7_linux.yml'
2024/07/18 00:18:02 wazuh-syscheckd: INFO: (6008): File integrity monitoring scan started.
2024/07/18 00:18:05 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_centos7_linux.yml'
2024/07/18 00:18:05 sca: INFO: Security Configuration Assessment scan finished. Duration: 16 seconds.
2024/07/18 00:18:06 wazuh-syscheckd: INFO: (6009): File integrity monitoring scan ended.
2024/07/18 00:20:31 rootcheck: INFO: Starting rootcheck scan.
2024/07/18 00:21:26 rootcheck: INFO: Ending rootcheck scan.
2024/07/18 00:22:35 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 00:22:43 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 01:22:44 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 01:22:51 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 02:22:52 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 02:22:59 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 03:23:00 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 03:23:07 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 04:23:08 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 04:23:15 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 05:23:16 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 05:23:23 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 06:23:24 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 06:23:31 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 07:23:32 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 07:23:39 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 08:17:36 wazuh-modulesd:syscollector: INFO: Stop received for Syscollector.
2024/07/18 08:17:36 wazuh-modulesd:syscollector: INFO: Module finished.
2024/07/18 08:17:36 wazuh-modulesd:vulnerability-scanner: INFO: Stopping vulnerability_scanner module.
2024/07/18 08:17:37 indexer-connector: WARNING: Failed to sync agent '010' with the indexer.
2024/07/18 08:17:37 wazuh-monitord: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:37 wazuh-logcollector: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:37 wazuh-remoted: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:37 wazuh-remoted: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:37 wazuh-syscheckd: INFO: (1756): Shutdown received. Releasing resources.
2024/07/18 08:17:37 wazuh-syscheckd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:38 wazuh-analysisd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:38 wazuh-execd: INFO: (1314): Shutdown received. Deleting responses.
2024/07/18 08:17:38 wazuh-execd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:38 wazuh-db: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:39 wazuh-db: INFO: Graceful process shutdown.
2024/07/18 08:17:39 wazuh-authd: INFO: (1225): SIGNAL [(15)-(Terminated)] Received. Exit Cleaning...
2024/07/18 08:17:40 wazuh-authd: INFO: Exiting...
2024/07/18 08:17:43 wazuh-modulesd:router: INFO: Loaded router module.
2024/07/18 08:17:43 wazuh-modulesd:content_manager: INFO: Loaded content_manager module.
2024/07/18 08:17:47 wazuh-csyslogd: INFO: Remote syslog server not configured. Clean exit.
2024/07/18 08:17:47 wazuh-dbd: INFO: Database not configured. Clean exit.
2024/07/18 08:17:47 wazuh-integratord: INFO: Remote integrations not configured. Clean exit.
2024/07/18 08:17:47 wazuh-agentlessd: INFO: Not configured. Exiting.
2024/07/18 08:17:47 wazuh-authd: INFO: Started (pid: 29378).
2024/07/18 08:17:47 wazuh-authd: INFO: Accepting connections on port 1515. No password required.
2024/07/18 08:17:47 wazuh-authd: INFO: Setting network timeout to 1.000000 sec.
2024/07/18 08:17:47 wazuh-db: INFO: Started (pid: 29392).
2024/07/18 08:17:48 wazuh-execd: INFO: Started (pid: 29418).
2024/07/18 08:17:49 wazuh-syscheckd: INFO: Started (pid: 29443).
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6003): Monitoring path: '/bin', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | scheduled'.
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6003): Monitoring path: '/boot', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | scheduled'.
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6003): Monitoring path: '/etc', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | scheduled'.
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6003): Monitoring path: '/sbin', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | scheduled'.
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6003): Monitoring path: '/usr/bin', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | scheduled'.
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6003): Monitoring path: '/usr/sbin', with options 'size | permissions | owner | group | mtime | inode | hash_md5 | hash_sha1 | hash_sha256 | scheduled'.
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/mtab'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/hosts.deny'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/mail/statistics'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/random-seed'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/random.seed'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/adjtime'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/httpd/logs'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/utmpx'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/wtmpx'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/cups/certs'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/dumpdates'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6206): Ignore 'file' entry '/etc/svc/volatile'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6207): Ignore 'file' sregex '.log$|.swp$'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6004): No diff for file: '/etc/ssl/private.key'
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6000): Starting daemon...
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6010): File integrity monitoring scan frequency: 43200 seconds
2024/07/18 08:17:49 wazuh-syscheckd: INFO: (6008): File integrity monitoring scan started.
2024/07/18 08:17:49 rootcheck: INFO: Starting rootcheck scan.
2024/07/18 08:17:49 wazuh-analysisd: INFO: Total rules enabled: '6786'
2024/07/18 08:17:49 wazuh-analysisd: INFO: Started (pid: 29430).
2024/07/18 08:17:49 wazuh-analysisd: INFO: (7200): Logtest started
2024/07/18 08:17:49 wazuh-analysisd: INFO: EPS limit disabled
2024/07/18 08:17:50 wazuh-remoted: INFO: Remote syslog allowed from: '
10.80.253.254/32'
2024/07/18 08:17:50 wazuh-remoted: INFO: Started (pid: 29511). Listening on port 514/UDP (syslog).
2024/07/18 08:17:50 wazuh-remoted: INFO: Started (pid: 29510). Listening on port 1514/TCP (secure).
2024/07/18 08:17:50 wazuh-remoted: INFO: (1410): Reading authentication keys file.
2024/07/18 08:17:51 wazuh-logcollector: INFO: Monitoring output of command(360): df -P
2024/07/18 08:17:51 wazuh-logcollector: INFO: Monitoring full output of command(360): netstat -tulpn | sed 's/\([[:alnum:]]\+\)\ \+[[:digit:]]\+\ \+[[:digit:]]\+\ \+\(.*\):\([[:digit:]]*\)\ \+\([0-9\.\:\*]\+\).\+\ \([[:digit:]]*\/[[:alnum:]\-]*\).*/\1 \2 == \3 == \4 \5/' | sort -k 4 -g | sed 's/ == \(.*\) ==/:\1/' | sed 1,2d
2024/07/18 08:17:51 wazuh-logcollector: INFO: Monitoring full output of command(360): last -n 20
2024/07/18 08:17:51 wazuh-logcollector: INFO: (1950): Analyzing file: '/var/log/audit/audit.log'.
2024/07/18 08:17:51 wazuh-logcollector: INFO: (1950): Analyzing file: '/var/ossec/logs/active-responses.log'.
2024/07/18 08:17:51 wazuh-logcollector: INFO: (1950): Analyzing file: '/var/log/messages'.
2024/07/18 08:17:51 wazuh-logcollector: INFO: (1950): Analyzing file: '/var/log/secure'.
2024/07/18 08:17:51 wazuh-logcollector: INFO: (1950): Analyzing file: '/var/log/maillog'.
2024/07/18 08:17:51 wazuh-logcollector: INFO: Started (pid: 29547).
2024/07/18 08:17:52 wazuh-monitord: INFO: Started (pid: 29566).
2024/07/18 08:17:53 wazuh-syscheckd: INFO: (6009): File integrity monitoring scan ended.
2024/07/18 08:17:53 wazuh-syscheckd: INFO: FIM sync module started.
2024/07/18 08:17:53 wazuh-modulesd:router: INFO: Loaded router module.
2024/07/18 08:17:53 wazuh-modulesd:content_manager: INFO: Loaded content_manager module.
2024/07/18 08:17:53 wazuh-modulesd: INFO: Started (pid: 29624).
2024/07/18 08:17:53 wazuh-modulesd:agent-upgrade: INFO: (8153): Module Agent Upgrade started.
2024/07/18 08:17:53 wazuh-modulesd:osquery: INFO: Module disabled. Exiting...
2024/07/18 08:17:53 wazuh-modulesd:ciscat: INFO: Module disabled. Exiting...
2024/07/18 08:17:53 sca: INFO: Module started.
2024/07/18 08:17:53 wazuh-modulesd:vulnerability-scanner: INFO: Starting vulnerability_scanner module.
2024/07/18 08:17:53 wazuh-modulesd:router: INFO: Starting router module.
2024/07/18 08:17:53 sca: INFO: Loaded policy '/var/ossec/ruleset/sca/cis_centos7_linux.yml'
2024/07/18 08:17:53 wazuh-modulesd:content_manager: INFO: Starting content_manager module.
2024/07/18 08:17:53 sca: INFO: Starting Security Configuration Assessment scan.
2024/07/18 08:17:53 wazuh-modulesd:database: INFO: Module started.
2024/07/18 08:17:53 wazuh-modulesd:download: INFO: Module started.
2024/07/18 08:17:53 wazuh-modulesd:control: INFO: Starting control thread.
2024/07/18 08:17:53 wazuh-modulesd:task-manager: INFO: (8200): Module Task Manager started.
2024/07/18 08:17:53 sca: INFO: Starting evaluation of policy: '/var/ossec/ruleset/sca/cis_centos7_linux.yml'
2024/07/18 08:17:53 wazuh-modulesd:syscollector: INFO: Module started.
2024/07/18 08:17:53 wazuh-modulesd:syscollector: INFO: Starting evaluation.
2024/07/18 08:17:54 wazuh-modulesd:syscollector: INFO: Evaluation finished.
2024/07/18 08:17:55 wazuh-modulesd:vulnerability-scanner: INFO: Vulnerability scanner module started
2024/07/18 08:17:59 indexer-connector: WARNING: IndexerConnector initialization failed for index 'wazuh-states-vulnerabilities-wazuh-server', retrying until the connection is successful.
2024/07/18 08:18:10 sca: INFO: Evaluation finished for policy '/var/ossec/ruleset/sca/cis_centos7_linux.yml'
2024/07/18 08:18:10 sca: INFO: Security Configuration Assessment scan finished. Duration: 17 seconds.