I managed to get rid of the new message by creating 
/var/ossec/queue/ossec/queue with user and group ossec.  Now a different 
error is showing (the ossec manual mentions it, but doesnt mention how to 
fix it):

Started ossec-remoted...
2015/02/23 22:23:24 ossec-syscheckd(1210): ERROR: Queue 
'/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
2015/02/23 22:23:24 ossec-rootcheck(1210): ERROR: Queue 
'/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
2015/02/23 22:23:32 ossec-syscheckd(1210): ERROR: Queue 
'/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
2015/02/23 22:23:32 ossec-rootcheck(1210): ERROR: Queue 
'/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
2015/02/23 22:23:45 ossec-syscheckd(1210): ERROR: Queue 
'/var/ossec/queue/ossec/queue' not accessible: 'Connection refused'.
2015/02/23 22:23:45 ossec-rootcheck(1211): ERROR: Unable to access queue: 
'/var/ossec/queue/ossec/queue'. Giving up..
ossec-syscheckd did not start correctly.

On Monday, February 23, 2015 at 9:48:45 PM UTC-5, C0nfus1i0n wrote:
>
> I restored from an even older backup and OSSEC is back, except i can't get 
> it to start.  Here's what happens when i restart its daemon:
>
> 2015/02/23 21:03:22 ossec-syscheckd(1210): ERROR: Queue 
> '/var/ossec/queue/ossec/
> queue' not accessible: 'Queue not found'.
> 2015/02/23 21:03:37 ossec-rootcheck(1210): ERROR: Queue 
> '/var/ossec/queue/ossec/
> queue' not accessible: 'No such file or directory'.
> 2015/02/23 21:03:48 ossec-syscheckd(1210): ERROR: Queue 
> '/var/ossec/queue/ossec/
> queue' not accessible: 'Queue not found'.
> 2015/02/23 21:04:03 ossec-rootcheck(1210): ERROR: Queue 
> '/var/ossec/queue/ossec/
> queue' not accessible: 'No such file or directory'.
>
> How do i fix that?
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to