Updated to ossec-hids-2.7-32 broke ossec-hids

Customer support forums for Atomic Protector (formerly Atomic Secured Linux). There is no such thing as a bad question here as long as it pertains to using Atomic Protector. Newbies feel free to get help getting started or asking questions that may be obvious. Regular users are asked to be gentle. :-)
biggles
Forum Regular
Forum Regular
Posts: 806
Joined: Tue Jul 15, 2008 2:38 pm
Location: Sweden
Contact:

Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by biggles »

I just updated to ossec-hids-2.7-32.el6.art.x86_64 and then ossec refused to start. No errors in the log file, just these lines being repeated with each restart:

Code: Select all

tail -n 7  /var/ossec/logs/ossec.log
2013/10/16 09:27:31 ossec-testrule: INFO: Reading decoder file etc/decoder.xml.
2013/10/16 09:27:31 ossec-testrule: INFO: Reading decoder file etc/decoders.d/01-asl-decoder.xml.
2013/10/16 09:27:31 ossec-testrule: INFO: Reading decoder file etc/decoders.d/10-asl-drupal-decoder.xml.
2013/10/16 09:27:31 ossec-testrule: INFO: Reading decoder file etc/decoders.d/50-asl-exim-decoder.xml.
2013/10/16 09:27:31 ossec-testrule: INFO: Reading decoder file etc/decoders.d/50-asl-waf-decoder.xml.
2013/10/16 09:27:31 ossec-testrule: INFO: Started (pid: 16383).
I have now downgraded to ossec-hids-2.7-24.el6.art.x86_64 and everything is back to normal.
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by scott »

You'll need to use ASL 4.0 from the -testing channel in order to be able to use ossec-2.7-32
biggles
Forum Regular
Forum Regular
Posts: 806
Joined: Tue Jul 15, 2008 2:38 pm
Location: Sweden
Contact:

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by biggles »

Ok, thanks. Maybe ossec-hids 2.7 only should be published in testing channel as well?
prupert
Forum Regular
Forum Regular
Posts: 573
Joined: Tue Aug 01, 2006 2:45 pm
Location: Netherlands

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by prupert »

biggles wrote:Ok, thanks. Maybe ossec-hids 2.7 only should be published in testing channel as well?
The stable channel offers 2.7-24, which works fine with ASL 3.
Lemonbit Internet Dedicated Server Management
biggles
Forum Regular
Forum Regular
Posts: 806
Joined: Tue Jul 15, 2008 2:38 pm
Location: Sweden
Contact:

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by biggles »

Strange. I have not enabled the testing channel and still got the update.

edit: checked again. Now it has been removed. I guess someone read my post...
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by mikeshinn »

It wasnt in the stable channel, is it possible you saw it in another channel?
biggles
Forum Regular
Forum Regular
Posts: 806
Joined: Tue Jul 15, 2008 2:38 pm
Location: Sweden
Contact:

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by biggles »

No chance Lance ;-)

I was in the stable channel. I installed it and then it broke. I downgraded and everything worked. Then I run yum update again and the upgrade was offered again. The day after the upgrade was gone. True story...
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by mikeshinn »

I'm positive it wasnt in the atomic stable channel, is it possible you got it from the nucleus channel? It is published there.
biggles
Forum Regular
Forum Regular
Posts: 806
Joined: Tue Jul 15, 2008 2:38 pm
Location: Sweden
Contact:

Re: Updated to ossec-hids-2.7-32 broke ossec-hids

Unread post by biggles »

Nope, got it from the tortix channel.
Post Reply