Question

Using OSSEC - huge size of /var/ossec/queue/diff

Posted May 6, 2015 15.7k views
UbuntuSecuritySystem Tools

Hi,

I’m using OSSEC on my Ubuntu server. I saw that the disk was almost full. I searched for the biggest folders and I found out that the folder /var/ossec/queue/diff was really huge and filling all the disk.

Is it normal? Is there a setting on OSSEC to prevent this from happening?

11 comments
  • Are you monitoring the OSSEC directory? That is, did you include /var/ossec or any of its sub-directories in the list of monitored directories in ossec.conf?

  • No, and I even added /var/ossec to be ignored with <ignore>/var/ossec</ignore>… I don’t see what else to do.

  • Show 8 more comments

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

×
2 answers

I think I found the issue. As I mentioned in a comment above, I installed Webmin after OSSEC. It looks like the cause of OSSEC using such a big amount of disk space is the Webmin system status (which is updated all the time).

I added the corresponding folder to the ignore list of OSSEC and it seems it solved the issue.

<ignore>/etc/webmin/system-status</ignore>

Thanks @finid for the many answers.

Cool! Happy for you.

Submit an Answer