Monitoring Splunk

ossec-analysisd: ERROR: read error

nickbijmoer
Path Finder

Hello guys, I get this error every time, someone knows how to fix it?

ossec-analysisd: ERROR: read error on /queue/diff/server/533/last-entry

Greetings,

Nick

0 Karma
1 Solution

hunters_splunk
Splunk Employee
Splunk Employee

Hi Nick,

Please try shutting down OSSEC, deleting that file (/queue/diff/server/533/last-entry), and starting OSSEC back up.

Hope it will work this time. Thanks!
Hunter

View solution in original post

hunters_splunk
Splunk Employee
Splunk Employee

Hi Nick,

Please try shutting down OSSEC, deleting that file (/queue/diff/server/533/last-entry), and starting OSSEC back up.

Hope it will work this time. Thanks!
Hunter

nickbijmoer
Path Finder

I think that worked 🙂 thanks !

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Great - glad know it worked!
Cheers
Hunter

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...