Wazuh agent binary for "Agent event queue is flooded" debug
- Check wazuh-agent version (
dpkg -l | grep wazuh-agent
) - Stop wazuh-agent.service (
systemctl stop wazuh-agent.service
) - Replace
/var/ossec/bin/ossec-agentd
to releases binary - Add
agent.debug=2
to/var/ossec/etc/local_internal_options.conf
- Start wazuh-agent.service (
systemctl start wazuh-agent.service
) - Check
/var/ossec/logs/ossec.log
(tail -F /var/ossec/logs/ossec.log | grep 'Send messages to buffer'
)