Search found 61 matches

by cponton
Mon Apr 11, 2022 8:10 am
Forum: OSSEC
Topic: Repo Version Missing Agent Addition
Replies: 1
Views: 36897

Re: Repo Version Missing Agent Addition

What agent version are you using? Do you not see the AELRQ options on the manager?
by cponton
Fri Mar 18, 2022 8:10 am
Forum: OSSEC
Topic: Duplicate counter error after upgrading to 3.6.0
Replies: 10
Views: 56916

Re: Duplicate counter error after upgrading to 3.6.0

Thank you. You can disable the counter by changing that remoted.verify_msg_id=1 option to a 0 or you can delete the agent counters Check your counters on both sides. The agent side should be higher that the HUB side # Agent side # cat /var/ossec/queue/rids/sender_counter 0:4243: # Manager side. Repl...
by cponton
Thu Mar 17, 2022 1:07 pm
Forum: OSSEC
Topic: Duplicate counter error after upgrading to 3.6.0
Replies: 10
Views: 56916

Re: Duplicate counter error after upgrading to 3.6.0

I see now.

Can you tell me what the setting is for remoted.verify_msg_id in /var/ossec/etc/internal_options.conf
by cponton
Thu Mar 17, 2022 7:51 am
Forum: OSSEC
Topic: Duplicate counter error after upgrading to 3.6.0
Replies: 10
Views: 56916

Re: Duplicate counter error after upgrading to 3.6.0

I think you may be saying that you have duplicate agent ids? If so you can remove them: Step 1: Use the manage agents service to remove the agent from the Manager. Provide the ID of the agent you want to remove: [root@atomic-manager ~]# /var/ossec/bin/manage_agents **********************************...
by cponton
Fri Jan 14, 2022 9:43 am
Forum: PHP Help and Discussion
Topic: PHP 5.6 end of support
Replies: 9
Views: 73261

Re: PHP 5.6 end of support

Andrew125 wrote: Thu Jan 13, 2022 9:09 am
mikeshinn wrote: Fri Dec 10, 2021 3:10 pm CentOS 7 is good through 2024. Or you can switch to Rocky Linux which is CentOS8 equivalent .Nulls Brawl Apk
What about RHEL?
Yes, RHEL is an option as well as it is supported through May 2024
by cponton
Fri Jan 07, 2022 10:13 am
Forum: OSSEC
Topic: Rootkit_files.txt update
Replies: 1
Views: 34647

Re: Rootkit_files.txt update

It's pushed to the agents inside a file called merged.mg in the /var/ossec/shared/default directory
by cponton
Thu Dec 16, 2021 9:43 am
Forum: OSSEC
Topic: oum update ERROR: Download failed with ERROR (6)
Replies: 17
Views: 122853

Re: oum update ERROR: Download failed with ERROR (6)

Atomicorp will be moving away from ElasticSearch and will be focusing on OpenSearch in the future. As for a timeline, it is not on the roadmap until later 2022.
by cponton
Thu Dec 16, 2021 9:39 am
Forum: OSSEC
Topic: Another agent disconnect issue
Replies: 2
Views: 36553

Re: Another agent disconnect issue

Please verify that the auth key on the client matches the corresponding agent ID on the HUB

https://www.ossec.net/docs/manual/agent ... sec-server
by cponton
Thu Nov 18, 2021 9:46 am
Forum: Requests
Topic: ClamAV 0.103.4 LTS
Replies: 7
Views: 59980

Re: ClamAV 0.103.4 LTS

Please let us know if you have any other issues! I apologize for the inconvenience
by cponton
Tue Nov 16, 2021 9:49 am
Forum: OSSEC
Topic: oum update ERROR: Download failed with ERROR (6)
Replies: 17
Views: 122853

Re: oum update ERROR: Download failed with ERROR (6)

Kakashi wrote: Tue Nov 16, 2021 1:52 am whatsapp mod
and rocky linux 8.5?
Yes. It is actually my go to for everyday :D
by cponton
Mon Nov 15, 2021 4:58 pm
Forum: OSSEC
Topic: Installation Error
Replies: 1
Views: 35077

Re: Installation Error

Are you trying to use oum to install? Or are you following the manual instructions?
by cponton
Wed Nov 10, 2021 9:05 am
Forum: OSSEC
Topic: oum update ERROR: Download failed with ERROR (6)
Replies: 17
Views: 122853

Re: oum update ERROR: Download failed with ERROR (6)

Currently the oum install is only supported on Centos/RheL 7/8, Rocky Linux 8, and Ubuntu 20.04. https://www.ossec.net/register-for-ossec/
by cponton
Tue Nov 09, 2021 4:14 pm
Forum: Requests
Topic: ClamAV 0.103.4 LTS
Replies: 7
Views: 59980

Re: ClamAV 0.103.4 LTS

Issue entered into GitLab and changes have been applied. Thanks!