Monitoring Splunk

ossec-analysisd: ERROR: read error

nickbijmoer
Path Finder

Hello guys, I get this error every time, someone knows how to fix it?

ossec-analysisd: ERROR: read error on /queue/diff/server/533/last-entry

Greetings,

Nick

0 Karma
1 Solution

hunters_splunk
Splunk Employee
Splunk Employee

Hi Nick,

Please try shutting down OSSEC, deleting that file (/queue/diff/server/533/last-entry), and starting OSSEC back up.

Hope it will work this time. Thanks!
Hunter

View solution in original post

hunters_splunk
Splunk Employee
Splunk Employee

Hi Nick,

Please try shutting down OSSEC, deleting that file (/queue/diff/server/533/last-entry), and starting OSSEC back up.

Hope it will work this time. Thanks!
Hunter

nickbijmoer
Path Finder

I think that worked 🙂 thanks !

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Great - glad know it worked!
Cheers
Hunter

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...