Splunk Search

Agent list in OSSEC agent status dashboard is empty

janfabo
Explorer

Hello. Yesterday I installed OSSEC & Splunk on server, and everything is working great, except two small things: OSSEC agent status shows No results found, although on ossec's agent_control -l I can see 12 agents, which are currently reporting. OSSEC agent coverage shows two agents: zeus and 10.10.10.10. How can I see them in this dashboard?
And 2nd thing is a bit trait: IP address of zeus is 10.10.10.10, how to cancel one of them?
Thanx for advice.

Tags (4)
0 Karma

southeringtonp
Motivator

If you can't see the agents, make sure that the agent management inputs scripts are working correctly. The most common issue is that either agent polling hasn't been configured or that it is seeing a password prompt and aborting.

First, make sure that you have configured the agent polling commands in ossec_servers.conf.

Then run the following and looking for errors:

cd /opt/splunk/etc/apps/ossec/bin
./ossec_agent_status.py
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...