[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Ossec-list] RE : RE : Installing a pre-compiled agent on another machine
- Subject: [Ossec-list] RE : RE : Installing a pre-compiled agent on another machine
- From: fcr-mailings at nerim.net (Fred)
- Date: Fri, 24 Mar 2006 13:17:19 +0100
I exported following on new machine:
/var/ossec
/etc/rc.d/init.d/ossec
.....and tried to run Ossec, but I have a problem:
#./bin/ossec-control status
ossec-execd is running...
ossec-agentd not running...
ossec-logcollector not running...
ossec-syscheckd not running...
In /var/ossec/logs, there are several messages like this:
ossec-syscheckd(1210): Queue '/var/ossec/queue/ossec/queue' not
accessible.
If somebody could help me, please.
Thanks
Fred
-----Original Message-----
From: ossec-list-bounces at ossec.net [mailto:ossec-list-bounces at ossec.net] On
Behalf Of Fred
Sent: Friday, March 24, 2006 12:24 PM
To: ossec-list at ossec.net
Subject: [Ossec-list] RE : Installing a pre-compiled agent on another
machine
Thanks for the answer.
Another question: should/must I create a user and a group "ossec" on servers
? If yes, how should I use them (to be secure):
- give root user rights to /var/ossec (default)
- give ossec group rights to /var/ossec (default)
- other...?
Thanks.
Fred
PS: I'll write a small "how to export pre-compiled agent"
-----Original Message-----
From: ahmet ozturk [mailto:oahmet at metu.edu.tr]
Sent: Thursday, March 23, 2006 4:17 PM
To: Fred
Cc: ossec-list at ossec.net
Subject: Re: [Ossec-list] Installing a pre-compiled agent on another machine
Hi Fred,
ossec client-installation installes the following binaries:
- manage_agents
- ossec-control
- ossec-logcollector
- ossec-agentd
- ossec-execd
- ossec-syscheckd
I think easiest way to do what you want would be make a prototype
installation on a client and copy the entire /var/ossec directory
on to other client machines.
then you should add the new client on server, extract its key and
import it in the client.
(please see: http://www.ossec.net/en/manual.html#manageagents)
also don't forget to customize the /var/ossec/etc/ossec.conf file
for localfiles, active responses, etc.
Regards,
~ahmet.
_______________________________________________
ossec-list mailing list
ossec-list at ossec.net
http://mailman.underlinux.com.br/mailman/listinfo/ossec-list
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.