[prev in list] [next in list] [prev in thread] [next in thread] 

List:       ossec-list
Subject:    [ossec-list] Re: Windows Agent Stops Unexpectedly
From:       Rob <jnrelliott () gmail ! com>
Date:       2006-12-05 15:56:55
Message-ID: 726c9a8e0612050756v612ad641p28fddb31c5674ff1 () mail ! gmail ! com
[Download RAW message or body]

Wow, that fixed it!  Thanks for your help!  I knew it had to be something
easy. Much appreciated.

Quick question - What's the minimum frequency time?  I was putting 60
seconds.


Robert

On 12/4/06, Daniel Cid <daniel.cid@gmail.com> wrote:
> 
> Hi Rob,
> 
> After examing and testing your config, I found the problem: If you do
> not provide
> any log file to be monitored on the ossec-agent, it will die
> unexpectedly like that.
> Nobody ever noticed this error because most of the times we monitor at
> least
> one log. I have a fix ready for the next version, but to solve your
> problem for
> now, you will need to provide at least one log to be monitored (it does
> not need
> to be valid).
> 
> For example, if you add the following to your ossec-agent config, it
> should
> work:
> 
> <ossec_config>
> <localfile>
> <location>C:\invalid.log</location>
> <log_format>syslog</log_format>
> </localfile>
> </ossec_config>
> 
> Let me know if this fixes your problem. If not, we will need to keep
> digging.
> 
> Thanks,
> 
> --
> Daniel B. Cid
> dcid ( at ) ossec.net
> 
> 
> On 11/29/06, Rob <jnrelliott@gmail.com> wrote:
> > Here's the agent config and log.  I've checked to make sure nothing was
> > running.  I ran the agent on a Windows 2003 SP1 Server, Windows 200 SP4,
> and
> > finally a Windows XP SP2 machine.  All of them stopping
> unexpectedly.  As
> > you can see in the log below, the agent is connecting and then the agent
> > dies mid-way.  This only happens in rare occasions.  The agent usually
> dies
> > right when it connects with the server.  I've verified port 1514 is open
> on
> > the server and I get connection notifications.
> > 
> > I greatly appreciate your help.
> > 
> > Robert
> > 
> > OSSEC.LOG
> > 
> > 2006/11/29 08:48:00 ossec-agent: DEBUG: Reading agent configuration.
> > 
> > 2006/11/29 08:48:00 ossec-agent: DEBUG: Reading logcollector
> configuration.
> > 
> > 2006/11/29 08:48:00 ossec-agent: DEBUG: Reading private keys.
> > 
> > 2006/11/29 08:48:00 ossec-agent: Assigning counter for agent testxpbox:
> > '0:1766'.
> > 
> > 2006/11/29 08:48:00 ossec-agent: Assigning sender counter: 0:66
> > 
> > 2006/11/29 08:48:00 ossec-agent: Connecting to server (10.65.8.23:1514).
> > 
> > 2006/11/29 08:48:00 ossec-agent: DEBUG: Creating thread mutex.
> > 
> > 2006/11/29 08:48:00 ossec-agent: Starting syscheckd thread.
> > 
> > 2006/11/29 08:48:15 ossec-agent(4101): Waiting for server reply (not
> > started).
> > 
> > 2006/11/29 08:48:24 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:48:24 ossec-agent: DEBUG: Checking if time elapsed to send
> > keep alive.
> > 
> > 2006/11/29 08:48:24 ossec-agent: DEBUG: Sending keep alive message.
> > 
> > 2006/11/29 08:48:24 ossec-agent: DEBUG: Sending keep alive: #!-Microsoft
> > Windows XP Professional x64 Edition Service Pack 1 (Build 3790)
> > 
> > 
> > 2006/11/29 08:52:05 ossec-agent(4101): Waiting for server reply (not
> > started).
> > 
> > 2006/11/29 08:52:15 ossec-agent: DEBUG: Checking if time elapsed to send
> > keep alive.
> > 
> > 2006/11/29 08:52:37 ossec-agent: DEBUG: Checking if time elapsed to send
> > keep alive.
> > 
> > 2006/11/29 08:53:00 ossec-agent: DEBUG: Checking if time elapsed to send
> > keep alive.
> > 
> > 2006/11/29 08:53:22 ossec-agent(4102): Connected to the server.
> > 
> > 2006/11/29 08:53:22 ossec-agent: DEBUG: Checking if time elapsed to send
> > keep alive.
> > 
> > 2006/11/29 08:53:22 ossec-agent: DEBUG: Entering LogCollectorStart().
> > 
> > 2006/11/29 08:53:27 ossec-agent: Server responded. Releasing lock.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '40960:33279:0:0:732f875d66358d83bc9281ae3a17d270:2c6f306d827f3cf05dd7a8d229fcf66bd537362a
> 
> > C:\dell/drivers/R96951/AEEnable.exe'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '23742:33206:0:0:fe9901280b768b37c069d282cd4ff93a:69f0122dd90857fa14f0ff2e85709843f7b2711a
> 
> > C:\dell/drivers/R96951/CPApp.ico'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '76:33206:0:0:ecc5e9367739f0462f5bd7a8cf96f6b1:c06c7f254c19322d6d595cb958433d7430d91d3c
> 
> > C:\dell/drivers/R96951/data.tag'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '1918256:33206:0:0:d4f44c040cf722e611d48d432157b3f4:f20f41a1970d17f640aea513f4503e0e2b60c87b
> 
> > C:\dell/drivers/R96951/data1.cab'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '76576:33206:0:0:521f4ae08e2d9674dbb7e68caea2ca65:1e6bce7400a26b3132c74422616d539d3153eeb3
> 
> > C:\dell/drivers/R96951/data1.hdr'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '512:33206:0:0:91f37ddc6786b521b7d76ec4739170a0:61916e52e4631551687c6a882da22605156e5cf3
> 
> > C:\dell/drivers/R96951/data2.cab'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '43520:33279:0:0:16155a03066c6c001a1bebdecd935b55:b5c1e0185cfc45c736a7961afe67284311ea5025
> 
> > C:\dell/drivers/R96951/devsetup.exe'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '460264:33206:0:0:0058f5dcee32d5ce4ccde57df72efadb:9da68aa1036f0bd796233ee3acadeb36d2e3a147
> 
> > C:\dell/drivers/R96951/engine32.cab'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '1539:33206:0:0:8c481f314ea4b4c8333741a0452f0424:ad8e784dd567ff7bee36cf0f746007c5fd1fba28
> 
> > C:\dell/drivers/R96951/layout.bin'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '397:33206:0:0:0580cd62777ccf7d0e0d171d433c402f:4d98d8cb70ced47c9892061fad25c4c48b3a2c33
> 
> > C:\dell/drivers/R96951/platform.cfg'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '6045:33206:0:0:b0ff76cc43157e594c8be3bdf1b2787a:e25ef9769ef1d3f3f56a6e323c8302d43b97bfe4
> 
> > C:\dell/drivers/R96951/readme.txt'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '116688:33279:0:0:1b9c9b566129b5d1331d4f356fa6efdf:1914b61bb6e4388a3836173e46538446d2dce153
> 
> > C:\dell/drivers/R96951/setup.exe'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '437812:33206:0:0:94d1151e8cf8103bb3557eefdca7c631:159f08df6543a5c14a0ca8f075a88ab700cdd77c
> 
> > C:\dell/drivers/R96951/setup.ibt'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '721:33206:0:0:bb02834aeba52dd040b3c9b5299682b9:d129c26365ed93b7380985cf690c656d9c73b6c8
> 
> > C:\dell/drivers/R96951/setup.ini'
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Attempting to send message to
> > server.
> > 
> > 2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server:
> > 
> '379842:33206:0:0:69c91712cd00eb6aa464b23531ab03df:4d4afdd5ee1c363ecd5cfe16b8414b95a3f4ac06
> 
> > C:\dell/drivers/R96951/setup.inx'
> > 
> > 
> > OSSEC.CONF
> > 
> > <ossec_config>
> > <client>
> > <!-- IP address of the Ossec HIDS server -->
> > <server-ip> 10.65.8.23</server-ip>
> > </client>
> > </ossec_config>
> > 
> > <!-- Default syscheck config -->
> > <ossec_config>
> > <syscheck>
> > <frequency>60</frequency>
> > <directories check_all="yes">C:\dell</directories>
> > </syscheck>
> > </ossec_config>
> > 
> > 
> > 
> > 
> > 
> > 
> > 
> > 
> > On 11/28/06, Daniel Cid <daniel.cid@gmail.com > wrote:
> > > 
> > > Hi Rob,
> > > 
> > > I really don't think it is a problem on the server. The agent should
> never
> > > "die" ungracefully like that. Can you show me you agent config and the
> > > agent log? It should be all under C:\program files\ossec-agent\ .
> > > 
> > > I never had a problem with the agent dying like that, but maybe a
> > different
> > > configuration is causing it... Btw, do you run any HIPS or something
> that
> > can
> > > interfere with the processes running? You can also enable debug on the
> > > agent to see what it is doing:
> > > 
> > > 
> > http://www.ossec.net/wiki/index.php/Community_manual:Debugging
> > > 
> > > *are you running version 0.9-3 on Windows? If not, try updating to
> it..
> > > 
> > > Thanks,
> > > 
> > > --
> > > Daniel B. Cid
> > > dcid ( at ) ossec.net
> > > 
> > > 
> > > 
> > > On 11/28/06, Rob <jnrelliott@gmail.com> wrote:
> > > > Just a bit more information.  Tried Ubuntu 6.10 server and got the
> same
> > > > result.  Also tried installing the agent on a XP box and it keeps
> > throwing
> > > > Dr. Watson errors.  At this point I can only hope it's an issue with
> > Ubuntu
> > > > and going to try out Fedora tommorrow.  It really does seem like
> it's an
> > > > issue only during the "sending" of the syscheck events that causes
> the
> > > > error.  Event log alerts are coming thru fine.
> > > > 
> > > > Robert
> > > > 
> > > > 
> > > > On 11/27/06, Rob <jnrelliott@gmail.com> wrote:
> > > > > The config and log files are below.  The server is running
> standard
> > Ubuntu
> > > > 6.06.  It was loaded without any modification except for installing
> the
> > > > ossec server.  I am receiving connection notifications when agents
> > connect
> > > > and disconnect.  The ossec server was installed several times with
> > different
> > > > options.  The logs and configs reflect the latest attempt without
> > installing
> > > > syscheck locally.
> > > > > 
> > > > > On top of that, I ran filemon and found the agent is doing hash
> checks
> > and
> > > > I can see the db file on the agent that has the hashes.  But it
> looks
> > like
> > > > when it attempts to send the file to the server is when the errors
> > happens
> > > > and the agent stops unexpectedly.
> > > > > 
> > > > > Thanks for the help.
> > > > > Robert
> > > > > 
> > > > > 
> > > > > ossec.conf file-
> > > > > <ossec_config>
> > > > > <global>
> > > > > <email_notification>yes</email_notification>
> > > > > <email_to> me@mycompany.com</email_to>
> > > > > <smtp_server>smtp.mycompany.com.com</smtp_server>
> > > > > <email_from>ossecm@testossec-desktop</email_from>
> > > > > </global>
> > > > > 
> > > > > <rules>
> > > > > <include>rules_config.xml</include>
> > > > > <include>pam_rules.xml</include>
> > > > > <include>sshd_rules.xml</include>
> > > > > <include>telnetd_rules.xml</include>
> > > > > <include>syslog_rules.xml</include>
> > > > > <include>arpwatch_rules.xml</include>
> > > > > <include>pix_rules.xml</include>
> > > > > <include>named_rules.xml</include>
> > > > > <include>smbd_rules.xml</include>
> > > > > <include>vsftpd_rules.xml</include>
> > > > > <include>pure-ftpd_rules.xml</include>
> > > > > <include>proftpd_rules.xml</include>
> > > > > <include>ms_ftpd_rules.xml</include>
> > > > > <include>hordeimp_rules.xml</include>
> > > > > <include>vpopmail_rules.xml</include>
> > > > > <include>web_rules.xml</include>
> > > > > <include>apache_rules.xml</include>
> > > > > <include>ids_rules.xml</include>
> > > > > <include>squid_rules.xml</include>
> > > > > <include>firewall_rules.xml</include>
> > > > > <include>netscreenfw_rules.xml</include>
> > > > > <include>postfix_rules.xml</include>
> > > > > <include>sendmail_rules.xml</include>
> > > > > <include>imapd_rules.xml</include>
> > > > > <include>mailscanner_rules.xml</include>
> > > > > <include>ms-exchange_rules.xml</include>
> > > > > <include>racoon_rules.xml</include>
> > > > > <include>spamd_rules.xml</include>
> > > > > <include>msauth_rules.xml</include>
> > > > > <!-- <include>policy_rules.xml</include> -->
> > > > > <include>attack_rules.xml</include>
> > > > > <include>local_rules.xml</include>
> > > > > <include>ossec_rules.xml</include>
> > > > > </rules>
> > > > > 
> > > > > 
> > > > > <active-response>
> > > > > <disabled>yes</disabled>
> > > > > </active-response>
> > > > > 
> > > > > 
> > > > > <remote>
> > > > > <connection>syslog</connection>
> > > > > </remote>
> > > > > 
> > > > > <remote>
> > > > > <connection>secure</connection>
> > > > > </remote>
> > > > > 
> > > > > <alerts>
> > > > > <log_alert_level>1</log_alert_level>
> > > > > <email_alert_level>7</email_alert_level>
> > > > > </alerts>
> > > > > <!-- Files to monitor (localfiles) -->
> > > > > 
> > > > > <localfile>
> > > > > <log_format>syslog</log_format>
> > > > > <location>/var/log/messages</location>
> > > > > </localfile>
> > > > > 
> > > > > <localfile>
> > > > > <log_format>syslog</log_format>
> > > > > <location>/var/log/auth.log</location>
> > > > > </localfile>
> > > > > 
> > > > > <localfile>
> > > > > <log_format>syslog</log_format>
> > > > > <location>/var/log/syslog</location>
> > > > > </localfile>
> > > > > 
> > > > > <localfile>
> > > > > <log_format>syslog</log_format>
> > > > > <location>/var/log/mail.info</location>
> > > > > </localfile>
> > > > > </ossec_config>
> > > > > 
> > > > > 
> > > > 
> > 
> ------------------------------------------------------------------------------------------------------------
> 
> > > > > ossec.log
> > > > > 
> > > > > 2006/11/22 14:39:38 ossec-syscheckd(1702): No directory provided
> for
> > > > 'directories' element.
> > > > > 2006/11/22 14:39:38 ossec-maild: Started (pid: 9570).
> > > > > 2006/11/22 14:39:38 ossec-execd: Started (pid: 9574).
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'rules_config.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'pam_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'sshd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'telnetd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'syslog_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'arpwatch_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'pix_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'named_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'smbd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'vsftpd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'pure-ftpd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'proftpd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'ms_ftpd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'hordeimp_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'vpopmail_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'web_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'apache_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'ids_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'squid_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'firewall_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'netscreenfw_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'postfix_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'sendmail_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'imapd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'mailscanner_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'ms-exchange_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'racoon_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'spamd_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'msauth_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > > > 'attack_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'local_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:
> > 'ossec_rules.xml'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Total rules enabled: '452'
> > > > > 2006/11/22 14:39:38 ossec-analysisd: Started (pid: 9578).
> > > > > 2006/11/22 14:39:38 ossec-remoted: Started (pid: 9586).
> > > > > 2006/11/22 14:39:38 ossec-remoted(1501): No IP or network allowed
> in
> > the
> > > > access list for syslog. No reason for running it. Exiting.
> > > > > 2006/11/22 14:39:38 ossec-remoted: Started (pid: 9588).
> > > > > 2006/11/22 14:39:38 ossec-syscheckd(1702): No directory provided
> for
> > > > 'directories' element.
> > > > > 2006/11/22 14:39:38 ossec-syscheckd: Syscheck disabled. Exiting.
> > > > > 2006/11/22 14:39:38 ossec-monitord: Started (pid: 9594).
> > > > > 2006/11/22 14:39:44 ossec-logcollector(1950): Analyzing file:
> > > > '/var/log/messages'.
> > > > > 2006/11/22 14:39:44 ossec-logcollector(1950): Analyzing file:
> > > > '/var/log/auth.log'.
> > > > > 2006/11/22 14:39:44 ossec-logcollector(1950): Analyzing file:
> > > > '/var/log/syslog'.
> > > > > 2006/11/22 14:39:44 ossec-logcollector(1950): Analyzing file:
> > > > '/var/log/mail.info'.
> > > > > 2006/11/22 14:39:44 ossec-logcollector: Started (pid: 9582).
> > > > > 
> > > > > 
> > > > > 
> > > > > 
> > > > > 
> > > > > On 11/23/06, Black CryptoKnight < black_cryptoknight@yahoo.com>
> wrote:
> > > > > > What do the ossec.log files on your ossec server and the client
> say?
> > > > > > 
> > > > > > 
> > > > > > Rob < jnrelliott@gmail.com> wrote:
> > > > > > Hello,
> > > > > > 
> > > > > > Installed ossec via server mode on Ubuntu, fresh install.  I
> was
> > > > able to get the server started and ran the manage_agents
> utility.  Got
> > the
> > > > needed key and ran the agent installer on my windows 2000 and
> windows
> > 2003
> > > > servers.  Port 1514 is not blocked and I'm getting notifications
> when
> > the
> > > > agents connect.  So far so good.  However, after about a minute or
> so,
> > the
> > > > agents stop unexpectedly with the error below.  I've uninstalled
> > VirusScan,
> > > > i've configured allow lists (on ossec server), but the agent keeps
> > stopping
> > > > and it seems it's during a syscheck.  The files/directories I scan
> are
> > test
> > > > ones with no real system value.  Is there anything else I can try to
> > keep
> > > > the agents from stopping?  I also get a Dr.Watson error, also below.
> > I've
> > > > ran Filemon and found the agent stops right after syscheck finishes
> it's
> > > > scan.
> > > > > > 
> > > > > > Any help would be great since I really want to use the product!
> > > > > > 
> > > > > > Thanks,
> > > > > > RObert
> > > > > > 
> > > > > > --------------------------------------
> > > > > > Event Type:    Information
> > > > > > Event Source:    DrWatson
> > > > > > Event Category:    None
> > > > > > Event ID:    4097
> > > > > > Date:        11/22/2006
> > > > > > Time:        10:23:11 AM
> > > > > > User:        N/A
> > > > > > Computer:    NTFWADPCTXP2
> > > > > > Description:
> > > > > > The application, C:\Program Files\ossec-agent\ossec-agent.exe,
> > generated
> > > > an application error The error occurred on 11/22/2006 @ 10:23:11.458The
> > > > exception generated was c0000005 at address 004346A5 (ossec_agent)
> > > > > > 
> > > > > > For more information, see Help and Support Center at
> > > > http://go.microsoft.com/fwlink/events.asp .
> > > > > > --------------------------------------
> > > > > > 
> > > > > > Event Type:    Error
> > > > > > Event Source:    Application Error
> > > > > > Event Category:    (100)
> > > > > > Event ID:    1000
> > > > > > Date:        11/22/2006
> > > > > > Time:        10:23:11 AM
> > > > > > User:        N/A
> > > > > > Computer:    NTFWADPCTXP2
> > > > > > Description:
> > > > > > Faulting application ossec-agent.exe, version 0.0.0.0, faulting
> > module
> > > > ossec-agent.exe, version 0.0.0.0, fault address 0x000346a5.
> > > > > > 
> > > > > > For more information, see Help and Support Center at
> > > > http://go.microsoft.com/fwlink/events.asp.
> > > > > > Data:
> > > > > > 0000: 41 70 70 6c 69 63 61 74   Applicat
> > > > > > 0008: 69 6f 6e 20 46 61 69 6c   ion Fail
> > > > > > 0010: 75 72 65 20 20 6f 73 73   ure  oss
> > > > > > 0018: 65 63 2d 61 67 65 6e 74   ec-agent
> > > > > > 0020: 2e 65 78 65 20 30 2e 30   .exe 0.0
> > > > > > 0028: 2e 30 2e 30 20 69 6e 20   .0.0 in
> > > > > > 0030: 6f 73 73 65 63 2d 61 67   ossec-ag
> > > > > > 0038: 65 6e 74 2e 65 78 65 20   ent.exe
> > > > > > 0040: 30 2e 30 2e 30 2e 30 20   0.0.0.0
> > > > > > 0048: 61 74 20 6f 66 66 73 65   at offse
> > > > > > 0050: 74 20 30 30 30 33 34 36   t 000346
> > > > > > 0058: 61 35                     a5
> > > > > > 
> > > > > > 
> > > > > > 
> > > > > > 
> > > > > > 
> > > > > > 
> > > > > > 
> > > > > > Visit Jamaica's Tech Portal http://www.techjamaica.com
> > > > > > 
> > > > > > ________________________________
> > > > Everyone is raving about the all-new Yahoo! Mail beta.
> > > > > 
> > > > > 
> > > > 
> > > > 
> > > 
> > 
> > 
> 


[Attachment #3 (text/html)]

Wow, that fixed it!&nbsp; Thanks for your help!&nbsp; I knew it had to be something \
easy. Much appreciated.<br><br>Quick question - What's the minimum frequency \
time?&nbsp; I was putting 60 seconds.<br><br><br>Robert<br><br><div><span \
class="gmail_quote"> On 12/4/06, <b class="gmail_sendername">Daniel Cid</b> &lt;<a \
href="mailto:daniel.cid@gmail.com">daniel.cid@gmail.com</a>&gt; \
wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, \
204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"> Hi Rob,<br><br>After \
examing and testing your config, I found the problem: If you do<br>not provide<br>any \
log file to be monitored on the ossec-agent, it will die<br>unexpectedly like \
that.<br>Nobody ever noticed this error because most of the times we monitor at least \
<br>one log. I have a fix ready for the next version, but to solve your problem \
for<br>now, you will need to provide at least one log to be monitored (it does not \
need<br>to be valid).<br><br>For example, if you add the following to your \
ossec-agent config, it should \
<br>work:<br><br>&lt;ossec_config&gt;<br>&nbsp;&nbsp;&lt;localfile&gt;<br>&nbsp;&nbsp; \
&nbsp;&nbsp;&lt;location&gt;C:\invalid.log&lt;/location&gt;<br>&nbsp;&nbsp;&nbsp;&nbsp \
;&lt;log_format&gt;syslog&lt;/log_format&gt;<br>&nbsp;&nbsp;&lt;/localfile&gt;<br>&lt;/ossec_config&gt;<br><br>
 Let me know if this fixes your problem. If not, we will need to keep \
digging.<br><br>Thanks,<br><br>--<br>Daniel B. Cid<br>dcid ( at ) <a \
href="http://ossec.net">ossec.net</a><br><br><br>On 11/29/06, Rob &lt;<a \
href="mailto:jnrelliott@gmail.com"> jnrelliott@gmail.com</a>&gt; wrote:<br>&gt; \
Here's the agent config and log.&nbsp;&nbsp;I've checked to make sure nothing \
was<br>&gt; running.&nbsp;&nbsp;I ran the agent on a Windows 2003 SP1 Server, Windows \
200 SP4, and<br>&gt; finally a Windows XP SP2 machine.&nbsp;&nbsp;All of them \
stopping unexpectedly.&nbsp;&nbsp;As <br>&gt; you can see in the log below, the agent \
is connecting and then the agent<br>&gt; dies mid-way.&nbsp;&nbsp;This only happens \
in rare occasions.&nbsp;&nbsp;The agent usually dies<br>&gt; right when it connects \
with the server.&nbsp;&nbsp;I've verified port 1514 is open on <br>&gt; the server \
and I get connection notifications.<br>&gt;<br>&gt; I greatly appreciate your \
help.<br>&gt;<br>&gt; Robert<br>&gt;<br>&gt; OSSEC.LOG<br>&gt;<br>&gt; 2006/11/29 \
08:48:00 ossec-agent: DEBUG: Reading agent configuration. \
<br>&gt;<br>&gt;&nbsp;&nbsp;2006/11/29 08:48:00 ossec-agent: DEBUG: Reading \
logcollector configuration.<br>&gt;<br>&gt; 2006/11/29 08:48:00 ossec-agent: DEBUG: \
Reading private keys.<br>&gt;<br>&gt; 2006/11/29 08:48:00 ossec-agent: Assigning \
counter for agent testxpbox: <br>&gt; '0:1766'.<br>&gt;<br>&gt; 2006/11/29 08:48:00 \
ossec-agent: Assigning sender counter: 0:66<br>&gt;<br>&gt; 2006/11/29 08:48:00 \
ossec-agent: Connecting to server (<a \
href="http://10.65.8.23:1514">10.65.8.23:1514</a> ).<br>&gt;<br>&gt; 2006/11/29 \
08:48:00 ossec-agent: DEBUG: Creating thread mutex.<br>&gt;<br>&gt; 2006/11/29 \
08:48:00 ossec-agent: Starting syscheckd thread.<br>&gt;<br>&gt; 2006/11/29 08:48:15 \
ossec-agent(4101): Waiting for server reply (not <br>&gt; started).<br>&gt;<br>&gt; \
2006/11/29 08:48:24 ossec-agent: DEBUG: Attempting to send message to<br>&gt; \
server.<br>&gt;<br>&gt; 2006/11/29 08:48:24 ossec-agent: DEBUG: Checking if time \
elapsed to send<br>&gt; keep alive. <br>&gt;<br>&gt; 2006/11/29 08:48:24 ossec-agent: \
DEBUG: Sending keep alive message.<br>&gt;<br>&gt; 2006/11/29 08:48:24 ossec-agent: \
DEBUG: Sending keep alive: #!-Microsoft<br>&gt; Windows XP Professional x64 Edition \
Service Pack 1 (Build 3790) <br>&gt;<br>&gt;<br>&gt; 2006/11/29 08:52:05 \
ossec-agent(4101): Waiting for server reply (not<br>&gt; started).<br>&gt;<br>&gt; \
2006/11/29 08:52:15 ossec-agent: DEBUG: Checking if time elapsed to send<br>&gt; keep \
alive.<br> &gt;<br>&gt; 2006/11/29 08:52:37 ossec-agent: DEBUG: Checking if time \
elapsed to send<br>&gt; keep alive.<br>&gt;<br>&gt; 2006/11/29 08:53:00 ossec-agent: \
DEBUG: Checking if time elapsed to send<br>&gt; keep alive.<br>&gt; <br>&gt; \
2006/11/29 08:53:22 ossec-agent(4102): Connected to the server.<br>&gt;<br>&gt; \
2006/11/29 08:53:22 ossec-agent: DEBUG: Checking if time elapsed to send<br>&gt; keep \
alive.<br>&gt;<br>&gt; 2006/11/29 08:53:22 ossec-agent: DEBUG: Entering \
LogCollectorStart(). <br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: Server \
responded. Releasing lock.<br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: DEBUG: \
Sending message to server:<br>&gt; \
'40960:33279:0:0:732f875d66358d83bc9281ae3a17d270:2c6f306d827f3cf05dd7a8d229fcf66bd537362a
 <br>&gt; C:\dell/drivers/R96951/AEEnable.exe'<br>&gt;<br>&gt; 2006/11/29 08:53:27 \
ossec-agent: DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; \
2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server: <br>&gt; \
'23742:33206:0:0:fe9901280b768b37c069d282cd4ff93a:69f0122dd90857fa14f0ff2e85709843f7b2711a<br>&gt; \
C:\dell/drivers/R96951/CPApp.ico'<br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to <br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'76:33206:0:0:ecc5e9367739f0462f5bd7a8cf96f6b1:c06c7f254c19322d6d595cb958433d7430d91d3c<br>&gt; \
C:\dell/drivers/R96951/data.tag' <br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'1918256:33206:0:0:d4f44c040cf722e611d48d432157b3f4:f20f41a1970d17f640aea513f4503e0e2b60c87b
 <br>&gt; C:\dell/drivers/R96951/data1.cab'<br>&gt;<br>&gt; 2006/11/29 08:53:27 \
ossec-agent: DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; \
2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server: <br>&gt; \
'76576:33206:0:0:521f4ae08e2d9674dbb7e68caea2ca65:1e6bce7400a26b3132c74422616d539d3153eeb3<br>&gt; \
C:\dell/drivers/R96951/data1.hdr'<br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to <br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'512:33206:0:0:91f37ddc6786b521b7d76ec4739170a0:61916e52e4631551687c6a882da22605156e5cf3<br>&gt; \
C:\dell/drivers/R96951/data2.cab' <br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'43520:33279:0:0:16155a03066c6c001a1bebdecd935b55:b5c1e0185cfc45c736a7961afe67284311ea5025
 <br>&gt; C:\dell/drivers/R96951/devsetup.exe'<br>&gt;<br>&gt; 2006/11/29 08:53:27 \
ossec-agent: DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; \
2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server: <br>&gt; \
'460264:33206:0:0:0058f5dcee32d5ce4ccde57df72efadb:9da68aa1036f0bd796233ee3acadeb36d2e3a147<br>&gt; \
C:\dell/drivers/R96951/engine32.cab'<br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to <br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'1539:33206:0:0:8c481f314ea4b4c8333741a0452f0424:ad8e784dd567ff7bee36cf0f746007c5fd1fba28<br>&gt; \
C:\dell/drivers/R96951/layout.bin' <br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'397:33206:0:0:0580cd62777ccf7d0e0d171d433c402f:4d98d8cb70ced47c9892061fad25c4c48b3a2c33
 <br>&gt; C:\dell/drivers/R96951/platform.cfg'<br>&gt;<br>&gt; 2006/11/29 08:53:27 \
ossec-agent: DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; \
2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server: <br>&gt; \
'6045:33206:0:0:b0ff76cc43157e594c8be3bdf1b2787a:e25ef9769ef1d3f3f56a6e323c8302d43b97bfe4<br>&gt; \
C:\dell/drivers/R96951/readme.txt'<br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to <br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'116688:33279:0:0:1b9c9b566129b5d1331d4f356fa6efdf:1914b61bb6e4388a3836173e46538446d2dce153<br>&gt; \
C:\dell/drivers/R96951/setup.exe' <br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'437812:33206:0:0:94d1151e8cf8103bb3557eefdca7c631:159f08df6543a5c14a0ca8f075a88ab700cdd77c
 <br>&gt; C:\dell/drivers/R96951/setup.ibt'<br>&gt;<br>&gt; 2006/11/29 08:53:27 \
ossec-agent: DEBUG: Attempting to send message to<br>&gt; server.<br>&gt;<br>&gt; \
2006/11/29 08:53:27 ossec-agent: DEBUG: Sending message to server: <br>&gt; \
'721:33206:0:0:bb02834aeba52dd040b3c9b5299682b9:d129c26365ed93b7380985cf690c656d9c73b6c8<br>&gt; \
C:\dell/drivers/R96951/setup.ini'<br>&gt;<br>&gt; 2006/11/29 08:53:27 ossec-agent: \
DEBUG: Attempting to send message to <br>&gt; server.<br>&gt;<br>&gt; 2006/11/29 \
08:53:27 ossec-agent: DEBUG: Sending message to server:<br>&gt; \
'379842:33206:0:0:69c91712cd00eb6aa464b23531ab03df:4d4afdd5ee1c363ecd5cfe16b8414b95a3f4ac06<br>&gt; \
C:\dell/drivers/R96951/setup.inx' <br>&gt;<br>&gt;<br>&gt; OSSEC.CONF<br>&gt;<br>&gt; \
&lt;ossec_config&gt;<br>&gt;&nbsp;&nbsp; \
&lt;client&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;!-- IP address of the Ossec HIDS \
server --&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;server-ip&gt; <a \
href="http://10.65.8.23">10.65.8.23 </a>&lt;/server-ip&gt;<br>&gt;&nbsp;&nbsp; \
&lt;/client&gt;<br>&gt; &lt;/ossec_config&gt;<br>&gt;<br>&gt; &lt;!-- Default \
syscheck config --&gt;<br>&gt; &lt;ossec_config&gt;<br>&gt;&nbsp;&nbsp; \
&lt;syscheck&gt;<br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;frequency&gt;60&lt;/frequency&gt; <br>&gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;directories check_all=&quot;yes&quot;&gt;C:\dell&lt;/directories&gt;<br>&gt;&nbsp;&nbsp; \
&lt;/syscheck&gt;<br>&gt; \
&lt;/ossec_config&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt; \
On 11/28/06, Daniel Cid &lt; <a \
href="mailto:daniel.cid@gmail.com">daniel.cid@gmail.com</a> &gt; wrote:<br>&gt; \
&gt;<br>&gt; &gt; Hi Rob,<br>&gt; &gt;<br>&gt; &gt; I really don't think it is a \
problem on the server. The agent should never<br>&gt; &gt; &quot;die&quot; \
ungracefully like that. Can you show me you agent config and the <br>&gt; &gt; agent \
log? It should be all under C:\program files\ossec-agent\ .<br>&gt; &gt;<br>&gt; &gt; \
I never had a problem with the agent dying like that, but maybe a<br>&gt; \
different<br>&gt; &gt; configuration is causing it... Btw, do you run any HIPS or \
something that <br>&gt; can<br>&gt; &gt; interfere with the processes running? You \
can also enable debug on the<br>&gt; &gt; agent to see what it is doing:<br>&gt; \
&gt;<br>&gt; &gt;<br>&gt; <a \
href="http://www.ossec.net/wiki/index.php/Community_manual:Debugging"> \
http://www.ossec.net/wiki/index.php/Community_manual:Debugging</a><br>&gt; \
&gt;<br>&gt; &gt; *are you running version 0.9-3 on Windows? If not, try updating to \
it..<br>&gt; &gt;<br>&gt; &gt; Thanks,<br>&gt; &gt;<br>&gt; &gt; -- <br>&gt; &gt; \
Daniel B. Cid<br>&gt; &gt; dcid ( at ) <a \
href="http://ossec.net">ossec.net</a><br>&gt; &gt;<br>&gt; &gt;<br>&gt; &gt;<br>&gt; \
&gt; On 11/28/06, Rob &lt;<a href="mailto:jnrelliott@gmail.com">jnrelliott@gmail.com \
</a>&gt; wrote:<br>&gt; &gt; &gt; Just a bit more information.&nbsp;&nbsp;Tried \
Ubuntu 6.10 server and got the same<br>&gt; &gt; &gt; result.&nbsp;&nbsp;Also tried \
installing the agent on a XP box and it keeps<br>&gt; throwing<br>&gt; &gt; &gt; Dr. \
Watson errors.&nbsp;&nbsp;At this point I can only hope it's an issue with <br>&gt; \
Ubuntu<br>&gt; &gt; &gt; and going to try out Fedora tommorrow.&nbsp;&nbsp;It really \
does seem like it's an<br>&gt; &gt; &gt; issue only during the &quot;sending&quot; of \
the syscheck events that causes the<br>&gt; &gt; &gt; error.&nbsp;&nbsp;Event log \
alerts are coming thru fine. <br>&gt; &gt; &gt;<br>&gt; &gt; &gt; Robert<br>&gt; &gt; \
&gt;<br>&gt; &gt; &gt;<br>&gt; &gt; &gt; On 11/27/06, Rob &lt;<a \
href="mailto:jnrelliott@gmail.com">jnrelliott@gmail.com</a>&gt; wrote:<br>&gt; &gt; \
&gt; &gt; The config and log files are below.&nbsp;&nbsp;The server is running \
standard <br>&gt; Ubuntu<br>&gt; &gt; &gt; 6.06.&nbsp;&nbsp;It was loaded without any \
modification except for installing the<br>&gt; &gt; &gt; ossec server.&nbsp;&nbsp;I \
am receiving connection notifications when agents<br>&gt; connect<br>&gt; &gt; &gt; \
and disconnect.&nbsp;&nbsp;The ossec server was installed several times with <br>&gt; \
different<br>&gt; &gt; &gt; options.&nbsp;&nbsp;The logs and configs reflect the \
latest attempt without<br>&gt; installing<br>&gt; &gt; &gt; syscheck locally.<br>&gt; \
&gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; On top of that, I ran filemon and found the \
agent is doing hash checks <br>&gt; and<br>&gt; &gt; &gt; I can see the db file on \
the agent that has the hashes.&nbsp;&nbsp;But it looks<br>&gt; like<br>&gt; &gt; &gt; \
when it attempts to send the file to the server is when the errors<br>&gt; \
happens<br>&gt; &gt; &gt; and the agent stops unexpectedly. <br>&gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; Thanks for the help.<br>&gt; &gt; &gt; &gt; \
Robert<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; \
ossec.conf file-<br>&gt; &gt; &gt; &gt; &lt;ossec_config&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;global&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;email_notification&gt;yes&lt;/email_notification&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;email_to&gt; <a \
href="mailto:me@mycompany.com">me@mycompany.com</a> &lt;/email_to&gt;<br>&gt; &gt; \
&gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;smtp_server&gt;<a \
href="http://smtp.mycompany.com.com">smtp.mycompany.com.com</a>&lt;/smtp_server&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;email_from&gt;ossecm@testossec-desktop&lt;/email_from&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;/global&gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;rules&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;rules_config.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;pam_rules.xml&lt;/include&gt; <br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;sshd_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;telnetd_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;syslog_rules.xml&lt;/include&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;arpwatch_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;pix_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;named_rules.xml&lt;/include&gt; \
<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;smbd_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;vsftpd_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;pure-ftpd_rules.xml&lt;/include&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;proftpd_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;ms_ftpd_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;hordeimp_rules.xml&lt;/include&gt; \
<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;vpopmail_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;ids_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;squid_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;firewall_rules.xml&lt;/include&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;netscreenfw_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;postfix_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;sendmail_rules.xml&lt;/include&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;imapd_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;mailscanner_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;ms-exchange_rules.xml&lt;/include&gt; \
<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;racoon_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;spamd_rules.xml&lt;/include&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;msauth_rules.xml&lt;/include&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;!-- &lt;include&gt;policy_rules.xml&lt;/include&gt; \
--&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;attack_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;include&gt;local_rules.xml&lt;/include&gt; <br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;include&gt;ossec_rules.xml&lt;/include&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; \
&lt;/rules&gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;active-response&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;disabled&gt;yes&lt;/disabled&gt; <br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;/active-response&gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; &lt;remote&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;connection&gt;syslog&lt;/connection&gt;<br>&gt; &gt; \
&gt; &gt;&nbsp;&nbsp; &lt;/remote&gt; <br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;remote&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;connection&gt;secure&lt;/connection&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; \
&lt;/remote&gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; \
&lt;alerts&gt; <br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;log_alert_level&gt;1&lt;/log_alert_level&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;email_alert_level&gt;7&lt;/email_alert_level&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;/alerts&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; &lt;!-- Files to \
monitor (localfiles) --&gt; <br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;localfile&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;log_format&gt;syslog&lt;/log_format&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;location&gt;/var/log/messages&lt;/location&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; \
&lt;/localfile&gt; <br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; \
&lt;localfile&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;log_format&gt;syslog&lt;/log_format&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;location&gt;/var/log/auth.log&lt;/location&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; \
&lt;/localfile&gt; <br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp; \
&lt;localfile&gt;<br>&gt; &gt; &gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;log_format&gt;syslog&lt;/log_format&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;location&gt;/var/log/syslog&lt;/location&gt;<br>&gt; \
&gt; &gt; &gt;&nbsp;&nbsp; &lt;/localfile&gt; <br>&gt; &gt; &gt; &gt;<br>&gt; &gt; \
&gt; &gt;&nbsp;&nbsp; &lt;localfile&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; &lt;log_format&gt;syslog&lt;/log_format&gt;<br>&gt; &gt; \
&gt; &gt;&nbsp;&nbsp;&nbsp;&nbsp; \
&lt;location&gt;/var/log/mail.info&lt;/location&gt;<br>&gt; &gt; &gt; \
&gt;&nbsp;&nbsp; &lt;/localfile&gt; <br>&gt; &gt; &gt; &gt; \
&lt;/ossec_config&gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; \
&gt;<br>&gt; ------------------------------------------------------------------------------------------------------------
 <br>&gt; &gt; &gt; &gt; ossec.log<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-syscheckd(1702): No directory provided for<br>&gt; &gt; \
&gt; 'directories' element.<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-maild: \
Started (pid: 9570). <br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-execd: Started \
(pid: 9574).<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading \
rules file:<br>&gt; &gt; &gt; 'rules_config.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-analysisd: Reading rules file: <br>&gt; 'pam_rules.xml'<br>&gt; &gt; \
&gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading rules file:<br>&gt; \
'sshd_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading \
rules file:<br>&gt; &gt; &gt; 'telnetd_rules.xml' <br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-analysisd: Reading rules file:<br>&gt; &gt; &gt; \
'syslog_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file:<br>&gt; &gt; &gt; 'arpwatch_rules.xml' <br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file:<br>&gt; \
'pix_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading \
rules file:<br>&gt; 'named_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 \
ossec-analysisd: Reading rules file: <br>&gt; 'smbd_rules.xml'<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file:<br>&gt; &gt; &gt; \
'vsftpd_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file: <br>&gt; &gt; &gt; 'pure-ftpd_rules.xml'<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file:<br>&gt; &gt; &gt; \
'proftpd_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file: <br>&gt; &gt; &gt; 'ms_ftpd_rules.xml'<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file:<br>&gt; &gt; &gt; \
'hordeimp_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file: <br>&gt; &gt; &gt; 'vpopmail_rules.xml'<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file:<br>&gt; \
'web_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading \
rules file: <br>&gt; &gt; &gt; 'apache_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-analysisd: Reading rules file:<br>&gt; 'ids_rules.xml'<br>&gt; &gt; \
&gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading rules file: <br>&gt; \
'squid_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading \
rules file:<br>&gt; &gt; &gt; 'firewall_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-analysisd: Reading rules file: <br>&gt; &gt; &gt; \
'netscreenfw_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file:<br>&gt; &gt; &gt; 'postfix_rules.xml'<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file: <br>&gt; &gt; &gt; \
'sendmail_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file:<br>&gt; 'imapd_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-analysisd: Reading rules file: <br>&gt; &gt; &gt; \
'mailscanner_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file:<br>&gt; &gt; &gt; 'ms-exchange_rules.xml'<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file: <br>&gt; &gt; &gt; \
'racoon_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file:<br>&gt; 'spamd_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-analysisd: Reading rules file: <br>&gt; &gt; &gt; \
'msauth_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: \
Reading rules file:<br>&gt; &gt; &gt; 'attack_rules.xml'<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-analysisd: Reading rules file: <br>&gt; \
'local_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 ossec-analysisd: Reading \
rules file:<br>&gt; 'ossec_rules.xml'<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 \
ossec-analysisd: Total rules enabled: '452'<br> &gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-analysisd: Started (pid: 9578).<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-remoted: Started (pid: 9586).<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-remoted(1501): No IP or network allowed in <br>&gt; the<br>&gt; &gt; \
&gt; access list for syslog. No reason for running it. Exiting.<br>&gt; &gt; &gt; \
&gt; 2006/11/22 14:39:38 ossec-remoted: Started (pid: 9588).<br>&gt; &gt; &gt; &gt; \
2006/11/22 14:39:38 ossec-syscheckd(1702): No directory provided for <br>&gt; &gt; \
&gt; 'directories' element.<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:38 \
ossec-syscheckd: Syscheck disabled. Exiting.<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:38 ossec-monitord: Started (pid: 9594).<br>&gt; &gt; &gt; &gt; 2006/11/22 \
14:39:44 ossec-logcollector(1950): Analyzing file: <br>&gt; &gt; &gt; \
'/var/log/messages'.<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:44 \
ossec-logcollector(1950): Analyzing file:<br>&gt; &gt; &gt; \
'/var/log/auth.log'.<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:44 \
ossec-logcollector(1950): Analyzing file: <br>&gt; &gt; &gt; \
'/var/log/syslog'.<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:44 \
ossec-logcollector(1950): Analyzing file:<br>&gt; &gt; &gt; \
'/var/log/mail.info'.<br>&gt; &gt; &gt; &gt; 2006/11/22 14:39:44 ossec-logcollector: \
Started (pid: 9582). <br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; On \
11/23/06, Black CryptoKnight &lt; <a href="mailto:black_cryptoknight@yahoo.com"> \
black_cryptoknight@yahoo.com</a>&gt; wrote:<br>&gt; &gt; &gt; &gt; &gt; What do the \
ossec.log files on your ossec server and the client say?<br>&gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; Rob &lt;  <a \
href="mailto:jnrelliott@gmail.com">jnrelliott@gmail.com</a>&gt; wrote:<br>&gt; &gt; \
&gt; &gt; &gt; Hello,<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; \
&gt;&nbsp;&nbsp;&nbsp;&nbsp; Installed ossec via server mode on Ubuntu, fresh \
install.&nbsp;&nbsp;I was <br>&gt; &gt; &gt; able to get the server started and ran \
the manage_agents utility.&nbsp;&nbsp;Got<br>&gt; the<br>&gt; &gt; &gt; needed key \
and ran the agent installer on my windows 2000 and windows<br>&gt; 2003<br>&gt; &gt; \
&gt; servers.&nbsp;&nbsp;Port 1514 is not blocked and I'm getting notifications when \
<br>&gt; the<br>&gt; &gt; &gt; agents connect.&nbsp;&nbsp;So far so \
good.&nbsp;&nbsp;However, after about a minute or so,<br>&gt; the<br>&gt; &gt; &gt; \
agents stop unexpectedly with the error below.&nbsp;&nbsp;I've uninstalled<br>&gt; \
VirusScan,<br>&gt; &gt; &gt; i've configured allow lists (on ossec server), but the \
agent keeps <br>&gt; stopping<br>&gt; &gt; &gt; and it seems it's during a \
syscheck.&nbsp;&nbsp;The files/directories I scan are<br>&gt; test<br>&gt; &gt; &gt; \
ones with no real system value.&nbsp;&nbsp;Is there anything else I can try \
to<br>&gt; keep<br> &gt; &gt; &gt; the agents from stopping?&nbsp;&nbsp;I also get a \
Dr.Watson error, also below.<br>&gt; I've<br>&gt; &gt; &gt; ran Filemon and found the \
agent stops right after syscheck finishes it's<br>&gt; &gt; &gt; scan.<br>&gt; &gt; \
&gt; &gt; &gt; <br>&gt; &gt; &gt; &gt; &gt; Any help would be great since I really \
want to use the product!<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; \
Thanks,<br>&gt; &gt; &gt; &gt; &gt; RObert<br>&gt; &gt; &gt; &gt; &gt;<br> &gt; &gt; \
&gt; &gt; &gt; --------------------------------------<br>&gt; &gt; &gt; &gt; &gt; \
Event Type:&nbsp;&nbsp;&nbsp;&nbsp;Information<br>&gt; &gt; &gt; &gt; &gt; Event \
Source:&nbsp;&nbsp;&nbsp;&nbsp;DrWatson<br>&gt; &gt; &gt; &gt; &gt; Event \
Category:&nbsp;&nbsp;&nbsp;&nbsp;None <br>&gt; &gt; &gt; &gt; &gt; Event \
ID:&nbsp;&nbsp;&nbsp;&nbsp;4097<br>&gt; &gt; &gt; &gt; &gt; \
Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;11/22/2006<br>&gt; &gt; &gt; \
&gt; &gt; Time:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;10:23:11 AM<br>&gt; \
&gt; &gt; &gt; &gt; User:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;N/A<br>&gt; \
&gt; &gt; &gt; &gt; Computer:&nbsp;&nbsp;&nbsp;&nbsp;NTFWADPCTXP2 <br>&gt; &gt; &gt; \
&gt; &gt; Description:<br>&gt; &gt; &gt; &gt; &gt; The application, C:\Program \
Files\ossec-agent\ossec-agent.exe,<br>&gt; generated<br>&gt; &gt; &gt; an application \
error The error occurred on 11/22/2006 @ 10:23: 11.458 The<br>&gt; &gt; &gt; \
exception generated was c0000005 at address 004346A5 (ossec_agent)<br>&gt; &gt; &gt; \
&gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; For more information, see Help and Support \
Center at<br>&gt; &gt; &gt;  <a \
href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a> \
.<br>&gt; &gt; &gt; &gt; &gt; --------------------------------------<br>&gt; &gt; \
&gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; Event Type:&nbsp;&nbsp;&nbsp;&nbsp;Error \
<br>&gt; &gt; &gt; &gt; &gt; Event Source:&nbsp;&nbsp;&nbsp;&nbsp;Application \
Error<br>&gt; &gt; &gt; &gt; &gt; Event \
Category:&nbsp;&nbsp;&nbsp;&nbsp;(100)<br>&gt; &gt; &gt; &gt; &gt; Event \
ID:&nbsp;&nbsp;&nbsp;&nbsp;1000<br>&gt; &gt; &gt; &gt; &gt; \
Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;11/22/2006<br>&gt; &gt; &gt; \
&gt; &gt; Time:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;10:23:11 AM <br>&gt; \
&gt; &gt; &gt; &gt; User:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;N/A<br>&gt; \
&gt; &gt; &gt; &gt; Computer:&nbsp;&nbsp;&nbsp;&nbsp;NTFWADPCTXP2<br>&gt; &gt; &gt; \
&gt; &gt; Description:<br>&gt; &gt; &gt; &gt; &gt; Faulting application \
ossec-agent.exe, version <a href="http://0.0.0.0"> 0.0.0.0</a>, faulting<br>&gt; \
module<br>&gt; &gt; &gt; ossec-agent.exe, version <a \
href="http://0.0.0.0">0.0.0.0</a>, fault address 0x000346a5.<br>&gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt; For more information, see Help and Support Center at \
<br>&gt; &gt; &gt; <a \
href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>.<br>&gt; \
&gt; &gt; &gt; &gt; Data:<br>&gt; &gt; &gt; &gt; &gt; 0000: 41 70 70 6c 69 63 61 \
74&nbsp;&nbsp; Applicat<br> &gt; &gt; &gt; &gt; &gt; 0008: 69 6f 6e 20 46 61 69 \
6c&nbsp;&nbsp; ion Fail<br>&gt; &gt; &gt; &gt; &gt; 0010: 75 72 65 20 20 6f 73 \
73&nbsp;&nbsp; ure&nbsp;&nbsp;oss<br>&gt; &gt; &gt; &gt; &gt; 0018: 65 63 2d 61 67 65 \
6e 74&nbsp;&nbsp; ec-agent<br>&gt; &gt; &gt; &gt; &gt; 0020: 2e 65 78 65 20 30 2e \
30&nbsp;&nbsp; .exe  0.0<br>&gt; &gt; &gt; &gt; &gt; 0028: 2e 30 2e 30 20 69 6e \
20&nbsp;&nbsp; .0.0 in<br>&gt; &gt; &gt; &gt; &gt; 0030: 6f 73 73 65 63 2d 61 \
67&nbsp;&nbsp; ossec-ag<br>&gt; &gt; &gt; &gt; &gt; 0038: 65 6e 74 2e 65 78 65 \
20&nbsp;&nbsp; ent.exe<br>&gt; &gt; &gt; &gt; &gt; 0040: 30 2e 30 2e 30 2e 30 \
20&nbsp;&nbsp;  <a href="http://0.0.0.0">0.0.0.0</a><br>&gt; &gt; &gt; &gt; &gt; \
0048: 61 74 20 6f 66 66 73 65&nbsp;&nbsp; at offse<br>&gt; &gt; &gt; &gt; &gt; 0050: \
74 20 30 30 30 33 34 36&nbsp;&nbsp; t 000346<br>&gt; &gt; &gt; &gt; &gt; 0058: 61 \
<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; \
&gt;<br>&gt; &gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; Visit Jamaica's Tech \
Portal  <a href="http://www.techjamaica.com">http://www.techjamaica.com</a><br>&gt; \
&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt; &gt; \
________________________________<br>&gt; &gt; &gt; Everyone is raving about the \
all-new Yahoo! Mail beta. <br>&gt; &gt; &gt; &gt;<br>&gt; &gt; &gt; &gt;<br>&gt; &gt; \
&gt;<br>&gt; &gt; &gt;<br>&gt; &gt;<br>&gt;<br>&gt;<br></blockquote></div><br>



[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic