1
0
-1

 Hello,

Please help.

I have a strange phenomenon.

I want to discover a linux devices that are lxc containers and a openaudit  server is also lxc in that local zone.

When i configure discover to search in local zone devices. It create me a list of almost empty devices.

In discovery log is:

ssh_helperssh_auditNo credentials valid for xxx.xxx.xxx.xxx

The root credentials are saved in credentials.

When i discover a single device  in the same zone it works and credentials are accepted.

What i'm doing wrong?

The second problem is: When i discover 1 IP (device) in local zone through "discover a single device"  it save in a device list unter ID 123 with whole Info

When i do discover the next ip in local zone, openaudit find and save the next device under ID 124 and after some seconds overwrite ID 123 with some new info from ID 124. ID 124 is disappear.  With the next Discovery is the same overwriting to ID123 and ID 125 is gone. ID 123 contains a mix information from first device and last device.

In discovery log i found:

  System Id provided differs from System Id found for sup_syslog  0.000000
process audit
  include_input_devicesdevicesUPDATE entry for new_client, System ID 165  0.000000
process audit
  m_devices_componenetsprocess_componentInserting change logs (user) for xxx.xxx.xxx.xx (new_client)  0.000000
process audit
  m_devices_componenetsprocess_componentInserting change logs (user_group) for xxx.xxx.xxx.xx (new_client)  0.000000
process audit
  m_devices_componenetsprocess_componentInserting change logs (software) for xxx.xxx.xxx.xx (new_client)  0.000000
process audit
  m_devices_componenetsprocess_componentInserting change logs (service) for xxx.xxx.xxx.xx (new_client)  0.000000
process audit
  m_devices_componenetsprocess_component

Inserting change logs (route) for  xxx.xxx.xxx.xx (new_client)

  0.000000
process audit
  m_devices_componenetsprocess_componentInserting change logs (netstat) for xxx.xxx.xxx.xx (new_client)  0.000000
process audit
  include_input_devicesdevicesCompleted processing audit result for new_client (System ID 123)

 

Pleace Help.

    CommentAdd your comment...

    1 answer

    1.  
      1
      0
      -1

      Paul, If you are a supported customer please send your issue through to support@opmantek.com

      I believe both issues you are seeing are related. Please refer to our Troubleshooting wiki: Troubleshooting as well as the Matching Devices: Matching Devices

      Adjusting your Matching Rules should address the overwrite, which will make the subnet audit stop overwriting each device that is found.

       

        CommentAdd your comment...