Remoted architecture and tuning¶
ossec-remoted receives events from OSSEC agents (secure mode) and from remote syslog
senders (UDP/TCP). See ossec.conf: Remote Options for when to use secure versus
syslog. Understanding its threading model helps when sizing syslog TCP
forwarders and tuning internal_options.conf.
Process model¶
One ossec-remoted process runs one detached thread per <remote> block in
ossec.conf (secure, syslog UDP, or syslog TCP). All listener sockets bind in the
main thread before the process drops privileges (setuid/chroot), so every listener can
use privileged ports in a single process.
Threading¶
Main thread — binds listeners, drops privileges, starts listener threads, waits on
SIGTERM. On shutdown it closes listener FDs and waits for syslog TCP pool work to finish.One thread per ``<remote>`` listener — secure, syslog UDP, or syslog TCP accept/read loop.
Syslog TCP only — each accepted client connection is handled by a bounded worker pool on that listener (not one process per connection).
Constraints¶
At most one secure
<remote>listener perossec-remotedprocess. Secure mode uses process-global keystore state and helper threads for active response forwarding.UDP syslog and secure listeners do not use the syslog TCP worker pool.
Secure mode internals¶
The secure listener uses three cooperating threads:
Receiver — reads agent data; logs go to
ossec-analysisd, control messages to the manager thread.AR forward — receives active-response commands from
ossec-analysisdlocally and forwards them to agents.Manager — sends outbound messages to agents.
Syslog TCP¶
A bounded thread pool handles each persistent TCP client (typical syslog forwarders).
When the pool is at capacity (remoted.syslog_tcp_worker_pool or
remoted.syslog_tcp_max_tasks), new connections are closed (backpressure). Size the
worker pool to match your expected number of concurrent forwarders.
Syslog UDP¶
The listener thread receives datagrams and forwards them to ossec-analysisd with no
worker pool.
Shutdown¶
On SIGTERM/SIGHUP, ossec-remoted closes listener sockets. Syslog TCP workers
use remoted.syslog_tcp_read_timeout so blocked recv() calls return periodically,
allowing graceful drain within about 60 seconds.
Tuning options¶
Set these in /var/ossec/etc/local_internal_options.conf:
See internal_options.conf: remoted and internal_options.conf: Global thread settings for full option reference.