strange error message from ossec-keepalive

1,439 views
Skip to first unread message

Andre Pawlowski

unread,
Dec 2, 2010, 11:27:56 AM12/2/10
to ossec...@googlegroups.com
Hi list,

I've got a strange error message from my ossec server that I don't
understand:

OSSEC HIDS Notification.
2010 Dec 02 09:48:40

Received From: kokyt0s->ossec-keepalive
Rule: 1002 fired (level 2) -> "Unknown problem somewhere in the system."
Portion of the log(s):

--MARK--:
&pQSW__BPa5S?%tyDTJ3-iCG2lz2dU))r(F%6tjp8wqpf=]IKFT%ND2kP]ua/W)3-6'eHduX$;$Axqq7Vr.dVZ1SUDSaH)4xTXCIieaEKv47LD-bU)SXMnXO/jPGKn3.!NGBR_5]jD2UoSV9)h%z8G%7.xhI;s)267.rV214O@t2#w)Z(k'UQp9]MyDERrOrG[-,e?iS@B3Rg/kGiR[g6mc0K)/]S]0'+?+'/.[r$fqBR^7iAjoPv4j6SWjeRsLGr%$3#p+buf&u_RC3i/mE3vS3*jp&B1qSJM431TmEg,YJ][ge;6-dJI69?-TB?!BI4?Uza63V3vMY3ake6ahj-%A-m_5lgab!OVR,!pR+;L]eLgilU

--END OF NOTIFICATION


Has anyone an idea what this means?

Regards

--

Andre Pawlowski

-------------------------------------------------------------------

Wenn eine Idee nicht zuerst absurd erscheint, taugt sie nichts.
-Albert Einstein

dan (ddp)

unread,
Dec 2, 2010, 12:10:12 PM12/2/10
to ossec...@googlegroups.com

I think it's "normal" (although I didn't think these messages were
going to be logged). It's definitely nothing to worry about. I think
the random text in the message is just padding to make the keep alives
indistinguishable from other messages based on packet size.

loyd.darby

unread,
Dec 2, 2010, 1:54:28 PM12/2/10
to ossec...@googlegroups.com
It means that a syslog message had one of these words in it:
core_dumped|failure|error|attack|bad |illegal
|denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted
MARK and the string of characters is actually part of the message and it
is likely a disk error.
It definitely should be looked at.

--
R. Loyd Darby, OSSIM-OCSE
Project Manager DOC/NOAA/NMFS
Infrastructure coordinator
Southeast Fisheries Science Center
305-361-4297

Andre Pawlowski

unread,
Dec 2, 2010, 4:06:22 PM12/2/10
to ossec...@googlegroups.com
I don't find this log entry in any of my logs. That means that there was
no syslog message with this text. Smart didn't detect anything strange
either.

Andre Pawlowski

-------------------------------------------------------------------

Poor is the pupil who does not surpass his master.
-Leonardo da Vinci

loyd.darby

unread,
Dec 2, 2010, 4:52:22 PM12/2/10
to ossec...@googlegroups.com
That leaves only a memory / buffer overflow kind of error . If it only
happened once I would not sweat it.
It is also "possible" that the log data got corrupted in transit (look
at netstat -s for host and client interfaces)
If it repeats, then I would relook at the logs, possibly with a
different tool.
Binary data in a log file can hide from editors so cat, grep and strings
are better tools.
I think it is unlikely that OSSEC bug can cause this but you could
re-install as a last resort.

--

dan (ddp)

unread,
Dec 2, 2010, 5:32:47 PM12/2/10
to ossec...@googlegroups.com
On Thu, Dec 2, 2010 at 4:52 PM, loyd.darby <Loyd....@noaa.gov> wrote:
> That leaves only a memory / buffer overflow kind of error .  If it only
> happened once I would not sweat it.
> It is also "possible" that the log data got corrupted in transit (look at
> netstat -s for host and client interfaces)
> If it repeats, then I would relook at the logs, possibly with a different
> tool.
> Binary data in a log file can hide from editors so cat, grep and strings are
> better tools.
> I think it is unlikely that OSSEC bug can cause this but you could
> re-install as a last resort.
>
>

Or it could be part of the keep alive messages in OSSEC:
(from src/logcollector/logcollector.c)
char *rand_keepalive_str(char *dst, int size)
{
static const char text[] = "abcdefghijklmnopqrstuvwxyz"
"ABCDEFGHIJKLMNOPQRSTUVWXYZ"
"0123456789"
"!@#$%^&*()_+-=;'[],./?";
int i, len = rand() % (size - 10);
strncpy(dst, "--MARK--: ", 12);
for ( i = 10; i < len; ++i )
{
dst[i] = text[rand() % (sizeof text - 1)];
}
dst[i] = '\0';
return dst;

Daniel Cid

unread,
Dec 2, 2010, 7:21:23 PM12/2/10
to ossec...@googlegroups.com
Yes, a bug on OSSEC. These messages are randomly generated and should not reach
analysisd.

Been fixed on the latest snapshot: http:/www.ossec.net/files/snapshots/

thanks,

Bib Kam

unread,
Mar 13, 2014, 4:37:16 AM3/13/14
to ossec...@googlegroups.com
Hello,

I'm using OSSEC 2.7 but i get still this alert!!
Please, how to resolve this issue ?

Thank you in advance

Joshua Garnett

unread,
Mar 13, 2014, 11:41:43 AM3/13/14
to ossec...@googlegroups.com
All,

I'm getting this alert also in 2.7.1.  I tried writing a rule to filter them, but it caused remoted to not want to work properly.  I'd welcome a hack at this point, if not a proper fix.

--Josh


--

---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Gary Mason

unread,
Jun 13, 2014, 5:56:47 AM6/13/14
to ossec...@googlegroups.com
I used to get this on 2.6 and still get them on 2.7.1
Presumably the snapshots in 2010 didn't have a full fix.
Would like to know the implications of this - is it really a bug that can be ignored or is there something else going on under the surface ?
Speaking as an admin of PCI-compliant systems who has twitchy bosses about things like this.

dan (ddp)

unread,
Jun 13, 2014, 7:44:56 AM6/13/14
to ossec...@googlegroups.com
On Fri, Jun 13, 2014 at 5:56 AM, Gary Mason <saxm...@gmail.com> wrote:
> I used to get this on 2.6 and still get them on 2.7.1
> Presumably the snapshots in 2010 didn't have a full fix.
> Would like to know the implications of this - is it really a bug that can be
> ignored or is there something else going on under the surface ?
> Speaking as an admin of PCI-compliant systems who has twitchy bosses about
> things like this.
>

It's harmless*. You can either ignore it, or help us fix it.

*It does take up storage space, so harmless is a judgement call. There
are no known downsides, other than this and time spent ignoring any
alerts.

Michael Starks

unread,
Jun 13, 2014, 10:12:42 AM6/13/14
to ossec...@googlegroups.com
On 2014-06-13 4:56, Gary Mason wrote:
> I used to get this on 2.6 and still get them on 2.7.1
> Presumably the snapshots in 2010 didn't have a full fix.
> Would like to know the implications of this - is it really a bug that
> can be ignored or is there something else going on under the surface ?
> Speaking as an admin of PCI-compliant systems who has twitchy bosses
> about things like this.

I think I saw a commit for this in 2.8. You might want to try that.

Ian Brown

unread,
Apr 4, 2019, 12:34:09 PM4/4/19
to ossec-list
I know this is an old thread but when I Googled, this was the top result, so I figured it would be okay to continue the discussion here.

I just received this today:

OSSEC HIDS Notification.
2019 Apr 04 12:31:45

Received From: server->ossec-keepalive

Rule: 1002 fired (level 2) -> "Unknown problem somewhere in the system."
Portion of the log(s):

--MARK--: gnetT9ILb_p+LIy(PF!1*#11NrDK!XIzsNS@4[4nwCd7s^c7ou*NbMiO3'GH/^oq!7KIjiWG;hVl-fATAla^fXx8QmY.]un5]fhT2lHU6KnfQ,Yyhghn3(D2/JZ'4ughAo0,$P/,[mb;iZq3nxy*X2]WTU.rwezW6Ha]=?=*Z;97?H(n4lM9vHz%J@a5^z!Po!KfrC-&8h?qO(*0.xEsmlOV-O8nvM2K5VP-F_pVJo@GaWaL)(3NM0QCitQ(n0wA3trcV_Y?c*FRI),9oir087,yI[kWd_-6iVr3=xk[i.L/*+8?.HhnWRMNMWd.LH3bLCmCZ@!q83obTEO/@V0&hgxb

Ubuntu 18.04 LTS
dpkg -s ossec-hids-server
Version: 3.2.0-6132bionic

From atomiccorp.com repo

We're on an upgrade cadence and it looks like there's a 3.3.0-6515bionic package listed as an upgrade, however when I went to the website to check for a change log, it's showing 3.2 as the latest?  Did this bug creep back in at some point and get fixed in 3.3.0, or does Dan still need help tracking this down?

The system seems to be functioning fine -- nothing notable in dmesg or syslog.  The server is mostly idle as we're just using for testing -- it's an m4.4xlarge instance in AWS.  Uptime shows 51 days, and this is the first time I've received this from the instance.
Reply all
Reply to author
Forward
0 new messages