[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Ossec-list] OSSEC seems to die occasionally



Every once in a while, the OSSEC analysis engine dies. I have no idea
where to begin to narrow down the cause.

I see msesages like these in the /var/ossec/ossec.log:

2006/04/17 22:48:49 ossec-analysisd: Started (pid: 5826).
2006/04/17 22:48:49 ossec-analysisd: Connected to 'queue/alerts/mailq' (mail queue)
2006/04/17 22:48:52 ossec-syscheckd: Started (pid: 5836).
2006/04/17 22:48:52 ossec-analysisd: Connected to '/queue/alerts/execq' (exec queue)
2006/04/17 22:48:55 ossec-logcollector: Analyzing file: /var/log/messages
2006/04/17 22:48:55 ossec-logcollector: Analyzing file: /var/log/secure
2006/04/17 22:48:55 ossec-logcollector: Analyzing file: /var/log/xferlog
2006/04/17 22:48:55 ossec-logcollector: Analyzing file: /var/log/radius/radius.log
2006/04/17 22:48:55 ossec-logcollector: Analyzing file: /var/log/httpd/error_log
2006/04/17 22:48:55 ossec-logcollector: Analyzing file: /var/log/httpd/access_log
2006/04/17 22:48:55 ossec-logcollector: Started (pid: 5830).
2006/04/17 23:12:32 ossec-syscheckd: socketerr
2006/04/17 23:12:32 ossec-syscheckd(1224): Error sending message to queue.
2006/04/17 23:12:34 ossec-logcollector: socketerr
2006/04/17 23:12:34 ossec-logcollector(1224): Error sending message to queue.
2006/04/17 23:12:35 ossec-syscheckd(1210): Queue '/var/ossec/queue/ossec/queue' not accessible.
2006/04/17 23:12:35 ossec-syscheckd(1211): Unable to access queue: '/var/ossec/queue/ossec/queue'. Giving up..
2006/04/17 23:12:37 ossec-logcollector(1210): Queue '/var/ossec/queue/ossec/queue' not accessible.
2006/04/17 23:12:37 ossec-logcollector(1211): Unable to access queue: '/var/ossec/queue/ossec/queue'. Giving up..

-- 
Kayvan A. Sylvan          | Proud husband of       | Father to my kids:
Sylvan Associates, Inc.   | Laura Isabella Sylvan, | Katherine Yelena (8/8/89)
http://sylvan.com/~kayvan | my beautiful Queen.    | Robin Gregory (2/28/92)


OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.