Hi Victor, Chema, or anyone else that's available.
We are preparing for a soon to come deployment for about 6k agents. I created a 2 manager cluster a couple months ago and left it in place running version 3.5.0 on CentOS 7. Today I noticed all service except authd and another are not running. After restarting and rebooting, it doesn't resolve. I see in the ossec.log there is a critical error that a PID file cannot be created. I have posted the actual error in the Wazuh group. I have seen tonight that the logcollector daemon tries to start up and has a PID but then seconds later it dies and no other daemons can run. I will post this information tomorrow morning.
https://groups.google.com/forum/#!topic/wazuh/LH8OFiX_OEc
A second question I have that is important is we've heard it is possible to pass Windows logs out of the manager in a Raw format, not the alerts in the alert.json file, so we can ingest those in Elastic Stack for search. Is this possible? If so, is there a documentation for it?
Best regards,
Robert
This message contains confidential and/or private information and is intended only for the individual named. If you are not the named addressee, any delivery, disclosure, dissemination or distribution of this e-mail is unlawful and strictly prohibited. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. E-mail transmissions cannot be guaranteed to be secure or without error, as information could be intercepted, corrupted, lost, destroyed, arrive late, be incomplete, or contain viruses. The sender therefore does not accept liability for any errors or omissions in the contents of this message, which errors or omissions arise as a result of e-mail transmission. If verification is required, please request a hard-copy version.
What is the installation folder of your manager? You can check it at the file "/etc/ossec-init.conf". It is possible that an incorrect path is being read by the manager and it is not able to find the sockets and files correctly.2018/10/16 16:43:13 ossec-logcollector: ERROR: (1210): Queue '/opt/<path>/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/MW2PR18MB23477070DBD71552C1511D58A8FF0%40MW2PR18MB2347.namprd18.prod.outlook.com.
For more options, visit https://groups.google.com/d/optout.
And try to start the manager again.chmod 770 /opt/<path>/ossec/var/run
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/67b629f3-8a1b-49da-8e7e-c60cb08dfe8b%40googlegroups.com.