Here are the 2 other threads that I found for this issue, but did not see a resolution in either of them.
2018/03/27 09:24:58 ossec-agent: INFO: Using notify time: 10 and max time to reconnect: 60
2018/03/27 09:24:58 ossec-agent: INFO: Started (pid: 6216).
2018/03/27 09:24:58 ossec-agent: INFO: (1410): Reading authentication keys file.
2018/03/27 09:24:58 ossec-agent: INFO: Trying to connect to server (<hidden>:1514).
2018/03/27 09:24:58 ossec-agent: INFO: Starting syscheckd thread.
2018/03/27 09:24:58 rootcheck: INFO: Started (pid: 6216).
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\comfile'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\exefile'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\piffile'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Directory'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Folder'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Security'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components [x64]'.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/regedit.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/system.ini', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/win.ini', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/at.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/attrib.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/cacls.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/cmd.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/drivers/etc', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/eventcreate.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/ftp.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/lsass.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/net.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/net1.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/netsh.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/reg.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/regedt32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/regsvr32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/runas.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/sc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/schtasks.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/sethc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/subst.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/wbem/WMIC.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/WindowsPowerShell\v1.0\powershell.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/winrm.vbs', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/at.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/attrib.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/cacls.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/cmd.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/drivers/etc', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/eventcreate.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/ftp.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/net.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/net1.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/netsh.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/reg.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regedit.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regedt32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regsvr32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/runas.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/sc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/schtasks.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/sethc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/subst.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/wbem/WMIC.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/WindowsPowerShell\v1.0\powershell.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/winrm.vbs', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Monitoring directory: 'C:\ProgramData/Microsoft/Windows/Start Menu/Programs/Startup', with options perm | size | owner | group | md5sum | sha1sum | realtime | mtime | inode.
2018/03/27 09:24:58 ossec-agent: INFO: Started (pid: 6216).
2018/03/27 09:24:58 ossec-agent: INFO: (4102): Connected to the server (<hidden>:1514).
2018/03/27 09:24:58 wazuh-modulesd:ciscat: INFO: Module disabled. Exiting...
2018/03/27 09:24:58 ossec-agent: INFO: System is Vista or newer (Microsoft Windows 7 Professional Service Pack 1 [Ver: 6.1.7601] - Wazuh v3.2.1).
2018/03/27 09:24:58 ossec-agent: INFO: (1951): Analyzing event log: 'Application'.
2018/03/27 09:24:58 ossec-agent: INFO: (1951): Analyzing event log: 'Security'.
2018/03/27 09:24:59 ossec-agent: INFO: (1951): Analyzing event log: 'System'.
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: INFO: Agent is restarting due to shared configuration changes.
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not move (tmp/Security-a06816) to (bookmarks/Security) which returned (5)
2018/03/27 09:24:59 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06816) to (bookmarks/Security) for (Security)
2018/03/27 09:24:59 ossec-agent: INFO: (1950): Analyzing file: 'C:\Program Files (x86)\ossec-agent\active-response\active-responses.log'.
2018/03/27 09:24:59 ossec-agent: INFO: Started (pid: 6216).
2018/03/27 09:24:59 ossec-agent: INFO: Received exit signal.
2018/03/27 09:24:59 ossec-agent: INFO: Exiting...
2018/03/27 09:24:59 ossec-agent: INFO: Using notify time: 10 and max time to reconnect: 60
2018/03/27 09:24:59 ossec-agent: INFO: Started (pid: 1524).
2018/03/27 09:24:59 ossec-agent: INFO: (1410): Reading authentication keys file.
2018/03/27 09:24:59 ossec-agent: INFO: Trying to connect to server (<hidden>:1514).
2018/03/27 09:25:00 ossec-agent: INFO: Starting syscheckd thread.
2018/03/27 09:25:00 rootcheck: INFO: Started (pid: 1524).
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\batfile'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\cmdfile'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\comfile'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\exefile'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\piffile'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\AllFilesystemObjects'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Directory'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Folder'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Classes\Protocols [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Policies [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Security'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\KnownDLLs'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurePipeServers\winreg'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\URL [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring registry entry: 'HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components [x64]'.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/regedit.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/system.ini', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/win.ini', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/at.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/attrib.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/cacls.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/cmd.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/drivers/etc', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/eventcreate.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/ftp.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/lsass.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/net.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/net1.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/netsh.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/reg.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/regedt32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/regsvr32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/runas.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/sc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/schtasks.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/sethc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/subst.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/wbem/WMIC.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/WindowsPowerShell\v1.0\powershell.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/SysNative/winrm.vbs', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/at.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/attrib.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/cacls.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/cmd.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/drivers/etc', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/eventcreate.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/ftp.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/net.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/net1.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/netsh.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/reg.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regedit.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regedt32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/regsvr32.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/runas.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/sc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/schtasks.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/sethc.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/subst.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/wbem/WMIC.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/WindowsPowerShell\v1.0\powershell.exe', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\Windows/System32/winrm.vbs', with options perm | size | owner | group | md5sum | sha1sum | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Monitoring directory: 'C:\ProgramData/Microsoft/Windows/Start Menu/Programs/Startup', with options perm | size | owner | group | md5sum | sha1sum | realtime | mtime | inode.
2018/03/27 09:25:00 ossec-agent: INFO: Started (pid: 1524).
2018/03/27 09:25:00 ossec-agent: INFO: (4102): Connected to the server (<hidden>:1514).
2018/03/27 09:25:00 wazuh-modulesd:ciscat: INFO: Module disabled. Exiting...
2018/03/27 09:25:00 ossec-agent: INFO: System is Vista or newer (Microsoft Windows 7 Professional Service Pack 1 [Ver: 6.1.7601] - Wazuh v3.2.1).
2018/03/27 09:25:00 ossec-agent: INFO: (1951): Analyzing event log: 'Application'.
2018/03/27 09:25:00 ossec-agent: INFO: (1951): Analyzing event log: 'Security'.
2018/03/27 09:25:00 ossec-agent: INFO: (1951): Analyzing event log: 'System'.
2018/03/27 09:25:00 ossec-agent: INFO: (1950): Analyzing file: 'C:\Program Files (x86)\ossec-agent\active-response\active-responses.log'.
2018/03/27 09:25:00 ossec-agent: INFO: Started (pid: 1524).
2018/03/27 09:25:01 ossec-agent: ERROR: Could not move (tmp/Security-a06248) to (bookmarks/Security) which returned (5)
2018/03/27 09:25:01 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06248) to (bookmarks/Security) for (Security)
2018/03/27 09:25:01 ossec-agent: ERROR: Could not move (tmp/Security-a06248) to (bookmarks/Security) which returned (5)
2018/03/27 09:25:01 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06248) to (bookmarks/Security) for (Security)
2018/03/27 09:25:01 ossec-agent: ERROR: Could not move (tmp/Security-a06248) to (bookmarks/Security) which returned (5)
2018/03/27 09:25:01 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06248) to (bookmarks/Security) for (Security)
2018/03/27 09:25:05 ossec-agent: ERROR: Could not move (tmp/Security-a06248) to (bookmarks/Security) which returned (5)
2018/03/27 09:25:05 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06248) to (bookmarks/Security) for (Security)
2018/03/27 09:25:15 ossec-agent: ERROR: Could not move (tmp/Security-a06248) to (bookmarks/Security) which returned (5)
2018/03/27 09:25:15 ossec-agent: ERROR: Could not rename_ex() temporary bookmark (tmp/Security-a06248) to (bookmarks/Security) for (Security)
2018/03/27 09:25:27 ossec-agent: ERROR: Could not move (tmp/Security-a06248) to (bookmarks/Security) which returned (5)