I got five of these alerts yesterday, but the "Previous output" is always the same. Should it be changing each time? Is it stored in /opt/ossec/queue/diff/ldap1/533 and if so, I can't seem to find a match for the previous output in any of the files stored there.
tcp 0 0 ::1:8389 :::* LISTEN
tcp 0 0 :::22 :::* LISTEN
tcp 0 0 :::2600 :::* LISTEN
tcp 0 0 :::389 :::* LISTEN
tcp 0 0 :::5432 :::* LISTEN
tcp 0 0 :::636 :::* LISTEN
Previous output:
ossec: output: 'netstat -tan |grep LISTEN |grep -v 127.0.0.1 | sort':
tcp 0 0
0.0.0.0:199 0.0.0.0:* LISTEN
tcp 0 0
0.0.0.0:20031 0.0.0.0:* LISTEN
tcp 0 0
0.0.0.0:5432 0.0.0.0:* LISTEN
tcp 0 0
0.0.0.0:8000 0.0.0.0:* LISTEN
tcp 0 0
0.0.0.0:8089 0.0.0.0:* LISTEN
[root@ossec 533]# ls -l
total 40
drwxr-x---. 2 ossec ossec 4096 Apr 5 08:45 .
drwxr-----. 3 ossec ossec 4096 Apr 3 09:22 ..
-rw-r-----. 1 ossec ossec 1049 Apr 5 08:45 last-entry
-rw-r-----. 1 ossec ossec 1078 Apr 3 09:22 state.1365006174
-rw-r-----. 1 ossec ossec 1049 Apr 3 09:45 state.1365007531
-rw-r-----. 1 ossec ossec 1138 Apr 4 21:24 state.1365135886
-rw-r-----. 1 ossec ossec 1049 Apr 4 21:30 state.1365136246
-rw-r-----. 1 ossec ossec 1138 Apr 5 04:44 state.1365162273
-rw-r-----. 1 ossec ossec 1049 Apr 5 04:50 state.1365162633
-rw-r-----. 1 ossec ossec 1138 Apr 5 08:39 state.1365176375