Troubleshooting OSSEC issues
From Notes_Wiki
<yambe:breadcrumb>OSSEC|OSSEC</yambe:breadcrumb>
Troubleshooting OSSEC issues
For troubleshooting OSSEC issues try following:
- Restart ossec service on ossec server
- Notice that ossec-remoted starts (use /var/ossec/bin/ossec-controld restart)
- Restart ossec service on client
- Verify details in /var/ossec/etc/ossec.conf file
- Verify key is same in /var/ossec/etc/client.keys in both server and client
- Restart ossec machine
- Restart client machine
- Look at /var/ossec/log/ossec.log file for hints