Using OSSEC - huge size of /var/ossec/queue/diff

May 6, 2015 13.5k views
Ubuntu Security System Tools

Hi,

I’m using OSSEC on my Ubuntu server. I saw that the disk was almost full. I searched for the biggest folders and I found out that the folder /var/ossec/queue/diff was really huge and filling all the disk.

Is it normal? Is there a setting on OSSEC to prevent this from happening?

11 comments
  • Are you monitoring the OSSEC directory? That is, did you include /var/ossec or any of its sub-directories in the list of monitored directories in ossec.conf?

  • No, and I even added /var/ossec to be ignored with <ignore>/var/ossec</ignore>… I don’t see what else to do.

  • Show 8 more comments
2 Answers

I think I found the issue. As I mentioned in a comment above, I installed Webmin after OSSEC. It looks like the cause of OSSEC using such a big amount of disk space is the Webmin system status (which is updated all the time).

I added the corresponding folder to the ignore list of OSSEC and it seems it solved the issue.

<ignore>/etc/webmin/system-status</ignore>

Thanks @finid for the many answers.

Cool! Happy for you.

Have another answer? Share your knowledge.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!