cat /var/ossec/logs/ossec.log | grep -i -E "(error|warning|critical)"
Hi Paul,
We fixed a bug recently that could be related. You can see it here:
https://github.com/wazuh/wazuh/pull/2871
To check if you are being affected, please, configure the option check_perm=no and change the whodata option to realtime in the directories tag.
So the agent must keep running and monitoring both drives without Whodata. We have also opened another issue to monitor different units of C with Whodata.
https://github.com/wazuh/wazuh/issues/2883
We are working to release the new version ASAP.
In case this solution is not enough, please, could you tell us which version of Wazuh is installed on the Windows servers?
Thank you for the report. Regards.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6ebf6f1a-b0a9-4be2-ab68-169b56514ecf%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.