Skip to content

Ossec 2.9.1 Reports not being sent out #1227

@hafeezy2j

Description

@hafeezy2j

I have recently, upgraded ossec from 2.8.3 to 2.9.1 and I have noticed that reports are being generated but not being sent out. These reports were being sent out without a hitch before the upgrade.

I see that in /var/ossec/logs/ossec.log, reports are being generated..

2017/08/16 00:01:59 ossec-monitord: INFO: Starting daily reporting for 'Daily report: File changes'
2017/08/16 00:02:05 ossec-monitord: INFO: Report 'Daily report: File changes' completed. Creating output...
2017/08/16 00:02:05 INFO: Connected to 1X2.30.XX.X1 at address 1X2.30.XX.X1, port 25

2017/08/16 00:02:45 ossec-monitord: INFO: Report 'Daily report: Windows Authentication Failure Report' completed. Creating output...
2017/08/16 00:02:45 INFO: Connected to 1X2.30.XX.X1 at address 1X2.30.XX.X1, port 25

2017/08/17 00:01:33 ossec-monitord: INFO: Starting daily reporting for 'Daily report: Authentication Failure Report'
2017/08/17 00:01:43 ossec-monitord: INFO: Report 'Daily report: Authentication Failure Report' completed. Creating output...
2017/08/17 00:01:43 ossec-monitord: INFO: Report 'Daily report: File changes' completed. Creating output...
2017/08/17 00:01:44 ossec-monitord: INFO: Report 'Daily report: Windows Authentication Failure Report' completed. Creating output...

2017/08/17 00:01:44 INFO: Connected to 1X2.30.XX.X1 at address 1X2.30.XX.X1, port 25
2017/08/17 00:01:44 INFO: Connected to 1X2.30.XX.X1 at address 1X2.30.XX.X1, port 25
2017/08/17 00:01:44 INFO: Connected to 1X2.30.XX.X1 at address 1X2.30.XX.X1, port 25

Here what I see in /var/log/messages which could be the culprit.

Aug 16 00:02:05 mtc-ossec-01p kernel: ossec-monitord[20805]: segfault at 17 ip 00007f4cba3908c5 sp 00007fff4f190950 error 4 in libc-2.12.so[7f4cba2ed000+18a000]
Aug 16 00:02:45 mtc-ossec-01p kernel: ossec-monitord[20817]: segfault at 17 ip 00007f4cba3908c5 sp 00007fff4f190950 error 4 in libc-2.12.so[7f4cba2ed000+18a000

Aug 17 00:01:44 mtc-ossec-01p kernel: ossec-monitord[11545]: segfault at 18 ip 00007f258b2798c5 sp 00007ffcce43b4a0 error 4 in libc-2.12.so[7f258b1d6000+18a000]
Aug 17 00:01:44 mtc-ossec-01p kernel: ossec-monitord[11615]: segfault at 18 ip 00007f258b2798c5 sp 00007ffcce43b4a0 error 4 in libc-2.12.so[7f258b1d6000+18a000]
Aug 17 00:01:44 mtc-ossec-01p kernel: ossec-monitord[11614]: segfault at 18 ip 00007f258b2798c5 sp 00007ffcce43b4a0 error 4 in libc-2.12.so[7f258b1d6000+18a000]

Any clue how to fix this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions