Is the agent connected to the manager?
Is the entry in the ayscheck db updated (/var/ossec/queue/syscheck)?
The frequency seems very low on the agent. I haven't seen much success with very low frequencies.
> --
>
> ---
> You received this message because you are subscribed to the Google Groups "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
On Jul 17, 2015 8:51 AM, "Oleg Makarov" <theoleg...@gmail.com> wrote:
>
> Yep, its active.
> I dont see anything in /var/ossec/queue/syscheck :(
>
Did you check on the manager? I apologize for not being more specific initially, but that info is stored on the manager.
> I also try to change frequency to 600 seconds, but still the same :(
>
That's still very low for checking 2 hashes for every file in the configured directories.
It can take some time for the agent.conf to get pushed to the agents. But if you're having problems with the normal setup, I imagine you'll continue to have the problems with the agent.conf.
Double check your alerts.log file for syscheck alerts related to the sshd_config file.