Dear,
i was using auto_ossec before without problem, and all was perfect.
Now, i reinstalled security onion and cannot add anymore new clients (tried on two instance and it is the same behavior).
On windows side after run i got:
auto_ossec.exe X.X.X.X [*] Connected to auto enrollment server at IP: X.X.X.X [*] Pulled hostname and IP, encrypted data, and now sending to server. [*] We received our new pairing key for OSSEC, closing server connection. [*] Something did not complete. Does this system have Internet access? Traceback (most recent call last): File "auto_ossec.py", line 369, in <module> NameError: name 'path' is not defined None
on linux/server side:
`root@so01:~/auto-ossec# python3 auto_server.py
[*] The auto enrollment OSSEC Server is now listening on 9654
Client connected with ('X.X.X.X', 50928)
Timeout exceeded.
<pexpect.pty_spawn.spawn object at 0x7fee78057dd8>
command: /var/ossec/bin/manage_agents
args: ['/var/ossec/bin/manage_agents']
searcher: None
buffer (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
before (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
after: <class 'pexpect.exceptions.TIMEOUT'>
match: None
match_index: None
exitstatus: None
flag_eof: False
pid: 26833
child_fd: 8
closed: False
timeout: 300
delimiter: <class 'pexpect.exceptions.EOF'>
logfile: None
logfile_read: None
logfile_send: None
maxread: 2000
ignorecase: False
searchwindowsize: None
delaybeforesend: 0.05
delayafterclose: 0.1
delayafterterminate: 0.1
Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 97, in expect_loop
incoming = spawn.read_nonblocking(spawn.maxread, timeout)
File "/usr/lib/python3/dist-packages/pexpect/pty_spawn.py", line 452, in read_nonblocking
raise TIMEOUT('Timeout exceeded.')
pexpect.exceptions.TIMEOUT: Timeout exceeded.
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "auto_server.py", line 224, in handle
provision_key(hostname, ipaddr)
File "auto_server.py", line 197, in provision_key
ossec_key = parse_client(hostname, ipaddr)
File "auto_server.py", line 81, in parse_client
child.expect("for the new agent")
File "/usr/lib/python3/dist-packages/pexpect/spawnbase.py", line 315, in expect
timeout, searchwindowsize, async)
File "/usr/lib/python3/dist-packages/pexpect/spawnbase.py", line 339, in expect_list
return exp.expect_loop(timeout)
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 104, in expect_loop
return self.timeout(e)
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 68, in timeout
raise TIMEOUT(msg)
pexpect.exceptions.TIMEOUT: Timeout exceeded.
<pexpect.pty_spawn.spawn object at 0x7fee78057dd8>
command: /var/ossec/bin/manage_agents
args: ['/var/ossec/bin/manage_agents']
searcher: None
buffer (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
before (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
after: <class 'pexpect.exceptions.TIMEOUT'>
match: None
match_index: None
exitstatus: None
flag_eof: False
pid: 26833
child_fd: 8
closed: False
timeout: 300
delimiter: <class 'pexpect.exceptions.EOF'>
logfile: None
logfile_read: None
logfile_send: None
maxread: 2000
ignorecase: False
searchwindowsize: None
delaybeforesend: 0.05
delayafterclose: 0.1
delayafterterminate: 0.1
Pairing complete. Terminating connection to client.
is something with new version of security onion or windows (win10 1803)?
tnx.
Dear,
i was using auto_ossec before without problem, and all was perfect.
Now, i reinstalled security onion and cannot add anymore new clients (tried on two instance and it is the same behavior).
On windows side after run i got:
auto_ossec.exe X.X.X.X [*] Connected to auto enrollment server at IP: X.X.X.X [*] Pulled hostname and IP, encrypted data, and now sending to server. [*] We received our new pairing key for OSSEC, closing server connection. [*] Something did not complete. Does this system have Internet access? Traceback (most recent call last): File "auto_ossec.py", line 369, in <module> NameError: name 'path' is not defined Noneon linux/server side:
`root@so01:~/auto-ossec# python3 auto_server.py
[*] The auto enrollment OSSEC Server is now listening on 9654
Client connected with ('X.X.X.X', 50928)
Timeout exceeded.
<pexpect.pty_spawn.spawn object at 0x7fee78057dd8>
command: /var/ossec/bin/manage_agents
args: ['/var/ossec/bin/manage_agents']
searcher: None
buffer (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
before (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
after: <class 'pexpect.exceptions.TIMEOUT'>
match: None
match_index: None
exitstatus: None
flag_eof: False
pid: 26833
child_fd: 8
closed: False
timeout: 300
delimiter: <class 'pexpect.exceptions.EOF'>
logfile: None
logfile_read: None
logfile_send: None
maxread: 2000
ignorecase: False
searchwindowsize: None
delaybeforesend: 0.05
delayafterclose: 0.1
delayafterterminate: 0.1
Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 97, in expect_loop
incoming = spawn.read_nonblocking(spawn.maxread, timeout)
File "/usr/lib/python3/dist-packages/pexpect/pty_spawn.py", line 452, in read_nonblocking
raise TIMEOUT('Timeout exceeded.')
pexpect.exceptions.TIMEOUT: Timeout exceeded.
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "auto_server.py", line 224, in handle
provision_key(hostname, ipaddr)
File "auto_server.py", line 197, in provision_key
ossec_key = parse_client(hostname, ipaddr)
File "auto_server.py", line 81, in parse_client
child.expect("for the new agent")
File "/usr/lib/python3/dist-packages/pexpect/spawnbase.py", line 315, in expect
timeout, searchwindowsize, async)
File "/usr/lib/python3/dist-packages/pexpect/spawnbase.py", line 339, in expect_list
return exp.expect_loop(timeout)
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 104, in expect_loop
return self.timeout(e)
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 68, in timeout
raise TIMEOUT(msg)
pexpect.exceptions.TIMEOUT: Timeout exceeded.
<pexpect.pty_spawn.spawn object at 0x7fee78057dd8>
command: /var/ossec/bin/manage_agents
args: ['/var/ossec/bin/manage_agents']
searcher: None
buffer (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
before (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
after: <class 'pexpect.exceptions.TIMEOUT'>
match: None
match_index: None
exitstatus: None
flag_eof: False
pid: 26833
child_fd: 8
closed: False
timeout: 300
delimiter: <class 'pexpect.exceptions.EOF'>
logfile: None
logfile_read: None
logfile_send: None
maxread: 2000
ignorecase: False
searchwindowsize: None
delaybeforesend: 0.05
delayafterclose: 0.1
delayafterterminate: 0.1
Pairing complete. Terminating connection to client.
is something with new version of security onion or windows (win10 1803)?
tnx.