Hi,
1. Active response is getting triggered for both Rule ID 550,554 if 
<expect> parameter is kept blank. 2.If <expect> parameter  is given value 
FILENAME then active response is not getting triggered for RULE ID 554 but 
is getting triggered for RULE ID 550. 3. Not receiving any error logs. 4. 
Kindly 
find the details of the ossec.conf file for which Active response is not 
getting trigerred for RULE ID 554.

---- ossec.conf -----
<command> <name>Test</name> <executable>syscheck-all.sh</executable> 
<expect>FILENAME</expect> </command> <active-response> 
<disabled>no</disabled> <command>Test</command> 
<location>defined-agent</location> <agent_id>78</agent_id> 
<rules_id>554,550</rules_id> </active-response>

--- ossec.conf ---
Please help troubleshot the issue.

Thanks & Regards
Aksha

-- 
Disclaimer: Privileged & confidential information is contained in this 
message (including all attachments). If you are not an intended recipient 
of this message, please destroy this message immediately and kindly notify 
the sender by reply e-mail. Any unauthorized use or dissemination of this 
message in any manner whatsoever, in whole or in part, is strictly 
prohibited. This e-mail, including all attachments hereto, is for 
discussion purposes only and shall not be deemed or construed otherwise 
unless expressly stated. Any views or opinions presented in this email are 
solely those of the author and do not necessarily represent that of NJ 
Group of Companies. This communication, including any attachments may not 
be free of viruses, interceptions or interference, and may not be 
compatible with your systems. You should carry out your own virus checks 
before opening any attachment to this e-mail. The sender of this e-mail and 
NJ Group of Companies shall not be liable for any damage that you may 
sustain as a result of viruses, incompleteness of this message, a delay in 
receipt of this message or computer problems experienced. This message has 
been scanned for viruses and dangerous content by NJGroup Email Server, and 
is believed to be clean.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to ossec-list+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/ossec-list/8dfb3e11-428a-4ca6-ba59-e62225267172n%40googlegroups.com.

Reply via email to