ossec-remoted: WARNING: Message queue is full (262144). Events may be lost.
ossec-analysisd: WARNING: Input buffer is full (1500000). Events may be lost.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ca821058-2362-4fa8-b5c6-00a48cbc4e62%40googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ca821058-2362-4fa8-b5c6-00a48cbc4e62%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/b10bdfe1-ab5b-422a-9550-42400d9ba7c1%40googlegroups.com.
[root@ip-10-0-0-72 Mar]# cat ossec-alerts-12-AZPAXAOS01.log | grep "2020-03-12T05:" | wc -l
1273
[root@ip-10-0-0-72 Mar]# cat ossec-alerts-12-AZPAXAOS01.log | grep "2020-03-12T06:" | wc -l
12832
[root@ip-10-0-0-72 Mar]# cat ossec-alerts-12-AZPAXAOS01.log | grep "2020-03-12T07:" | wc -l
12261
[root@ip-10-0-0-72 Mar]# cat ossec-alerts-12-AZPAXAOS01.log | grep "2020-03-12T07:02:" | wc -l
1633
[root@ip-10-0-0-72 Mar]# cat ossec-alerts-12-AZPAXAOS01.log | grep "2020-03-12T08:" | wc -l
927
An example of the spike here
{"win":{"system":{"providerName":"Dynamics Server 01","eventID":"110","level":"2","task":"0","keywords":"0x80000000000000","systemTime":"2020-03-12T07:03:59.965448700Z","eventRecordID":"6650397","channel":"Application","computer":"AZ-PAX-AOS01.hosted.domain.local","severityValue":"ERROR","message":"Object Server 01: User 'MauP' is not authorised to select a record in table 'CustPackingSlipSalesLink'. Request denied."},"eventdata":{"data":"Object Server 01:, User 'MauP' is not authorised to select a record in table 'CustPackingSlipSalesLink'. Request denied."}}}
{"win":{"system":{"providerName":"Dynamics Server 01","eventID":"110","level":"2","task":"0","keywords":"0x80000000000000","systemTime":"2020-03-12T07:03:59.965448700Z","eventRecordID":"6650397","channel":"Application","computer":"AZ-PAX-AOS01.hosted.domain.local","severityValue":"ERROR","message":"Object Server 01: User 'MauP' is not authorised to select a record in table 'CustPackingSlipSalesLink'. Request denied."},"eventdata":{"data":"Object Server 01:, User 'MauP' is not authorised to select a record in table 'CustPackingSlipSalesLink'. Request denied."}}}
However I did notice something interesting here
| @timestamp | Mar 12, 2020 @ 09:02:59.894 |
| _id | -k-NzXABANMpWbSJtWTT |
| _index | wazuh-alerts-3.x-2020.03.12 |
| _score | 1 |
| _type | _doc |
| agent.id | 006 |
| agent.ip | 10.102.12.8 |
| agent.name | AZ-PAX-AOS01 |
| cluster.name | wazuh |
| cluster.node | wazuh-master |
| data.win.eventdata.data | Object Server 01:, User 'MauP' is not authorised to select a record in table 'CustPackingSlipSalesLink'. Request denied. |
| data.win.system.channel | Application |
| data.win.system.computer | AZ-PAX-AOS01.hosted.domain.local |
| data.win.system.eventID | 110 |
| data.win.system.eventRecordID | 6617292 |
| data.win.system.keywords | 0x80000000000000 |
| data.win.system.level | 2 |
| data.win.system.message | Object Server 01: User 'MauP' is not authorised to select a record in table 'CustPackingSlipSalesLink'. Request denied. |
| data.win.system.providerName | Dynamics Server 01 |
| data.win.system.severityValue | ERROR |
| data.win.system.systemTime | 2020-03-12T07:01:29.620933300Z |
There is a 2 hour discrepency between systemtime and timestamp. Perhaps this is causing confusion as to when the flooding is actually occurring?
That being said, I dont seem to find any alerts that are breaching the 500EPS rate.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ca821058-2362-4fa8-b5c6-00a48cbc4e62%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
[root@ip-10-0-0-72 Mar]# cat ossec-alerts-12-AZPAXAOS01.log | grep "2020-03-12T06:" | wc -l
12832
[root@ip-10-0-0-72 Mar]# cat ossec-alerts-12-AZPAXAOS01.log | grep "2020-03-12T07:" | wc -l
12261
They do not look very high enough to flood the queue, but could be the case if you are also experiencing disconnections or some other network problems. Could that be the case?
Can you send me your client_buffer stanza configuration? just in case we are missing out on something.
Best Regards,
Nicolas
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ca821058-2362-4fa8-b5c6-00a48cbc4e62%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/b10bdfe1-ab5b-422a-9550-42400d9ba7c1%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ad966387-6eee-4de6-807a-4c3c962193fb%40googlegroups.com.