Re: [ossec-list] Re: Active response not working for rule_id 554 with "filename" as expect

2022-03-03 Thread 'Aksha Gandhi | Information Security' via ossec-list
Hi, We are using AlienVault Version: OSSIM 5.7.4 For scripts we are referring to : https://github.com/jonschipp/nsm-tools/ The script is getting executed but we are not receiving FILENAME parameter when RULE ID 554 is getting triggered. Thanks in advance. On Thu, Mar 3, 2022 at 5:45 PM Manuel

Re: [ossec-list] Re: Active response not working for rule_id 554 with "filename" as expect

2022-03-04 Thread 'Aksha Gandhi | Information Security' via ossec-list
Hi, Thank you for your detailed explanation. I would like to discuss my scenario in detail so we could have a good understanding on our issue. *Case1*: I will be creating a new file(march4.txt) generating rule ID 554 and also editing an existing file(march.txt) generating rule ID 551. This is the