# curl --insecure "https://redacted-IP:55000/agents?select=status&pretty" -u wapi:redacted-password
{
"error": 0,
"data": {
"totalItems": 10,
"items": [
{
"status": "Active",
"id": "000"
},
{
"status": "Disconnected",
"id": "001"
},
{
"status": "Disconnected",
"id": "003"
},
{
"status": "Disconnected",
"id": "004"
},
{
"status": "Disconnected",
"id": "005"
},
{
"status": "Disconnected",
"id": "006"
},
{
"status": "Disconnected",
"id": "009"
},
{
"status": "Disconnected",
"id": "010"
},
{
"status": "Disconnected",
"id": "011"
},
{
"status": "Disconnected",
"id": "012"
}
]
}
}
# ls /var/ossec/logs/ossec.log
ls: cannot access /var/ossec/logs/ossec.log: No such file or directory
# zgrep ERROR /var/ossec/logs/ossec/2018/Mar/ossec-04.log.gz >ERROR.log
# zgrep WARNING /var/ossec/logs/ossec/2018/Mar/ossec-04.log.gz >WARNING.log
# grep ERROR /var/ossec/logs/ossec.logs
2018/03/06 06:14:09 ossec-analysisd: ERROR: at sc_send_db(): received: 'err Cannot save HW information.'
2018/03/06 06:14:09 ossec-remoted: ERROR: socketerr (not available).
2018/03/06 06:14:09 ossec-remoted: ERROR: (1210): Queue '/queue/ossec/queue' not accessible: 'Connection refused'.
2018/03/06 06:14:09 ossec-logcollector: ERROR: socketerr (not available).
2018/03/06 06:14:09 ossec-logcollector: ERROR: (1224): Error sending message to queue.
2018/03/06 06:14:12 ossec-remoted: ERROR: (1210): Queue '/queue/ossec/queue' not accessible: 'Connection refused'.
2018/03/06 06:14:12 ossec-logcollector: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
2018/03/06 06:14:51 wazuh-modulesd: ERROR: socketerr (not available).
# rpm --setperms wazuh-manager# rpm --setugids wazuh-manager# timedatectl set-timezone America/New_York# reboot