Skip to content

Wazuh error: connection refused with new SecureStack Base CentOS 7 install #1

@6mile

Description

@6mile

I added this ticket for a customer 17/3/2018

Hello,
our customer ask us to try SecureStack solution and then implement as one of the security layers. I was able to setup server from Your's ami, hovewer when i'm trying to setup worker from Centos 7 AMI https://aws.amazon.com/marketplace/pp/B0777BXSLW?qid=1521212736914&sr=0-3&ref_=srh_res_product_title (I'm getting errors from wazzuh deamon:

mar 16 15:02:30 securestack01 wazuh-agent[2679]: Starting OSSEC: 2018/03/16 15:02:30 ossec-agentd: INFO: Using notify time: 600 and max time to reconnect: 1800
mar 16 15:02:33 securestack01 wazuh-agent[2679]: 2018/03/16 15:02:33 ossec-syscheckd: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
mar 16 15:02:33 securestack01 wazuh-agent[2679]: 2018/03/16 15:02:33 rootcheck: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
mar 16 15:02:41 securestack01 wazuh-agent[2679]: 2018/03/16 15:02:41 ossec-syscheckd: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
mar 16 15:02:41 securestack01 wazuh-agent[2679]: 2018/03/16 15:02:41 rootcheck: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
mar 16 15:02:54 securestack01 wazuh-agent[2679]: 2018/03/16 15:02:54 ossec-syscheckd: ERROR: (1210): Queue '/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
mar 16 15:02:54 securestack01 wazuh-agent[2679]: 2018/03/16 15:02:54 rootcheck: CRITICAL: (1211): Unable to access queue: '/var/ossec/queue/ossec/queue'. Giving up..
mar 16 15:02:54 securestack01 wazuh-agent[2679]: [FAILED]
mar 16 15:02:54 securestack01 systemd[1]: wazuh-agent.service: control process exited, code=exited status=1
mar 16 15:02:54 securestack01 systemd[1]: Failed to start SYSV: Starts and stops Wazuh (Host Intrusion Detection System).
earlier steps like update, and setup were ok. Could You tell me how can i fix that error? If the tests will be successful our customer will use Your solution to protect whole infrastructure.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions