Hi, We are using AlienVault Version: OSSIM 5.7.4 For scripts we are referring to : https://github.com/jonschipp/nsm-tools/ The script is getting executed but we are not receiving FILENAME parameter when RULE ID 554 is getting triggered.
Thanks in advance. On Thu, Mar 3, 2022 at 5:45 PM Manuel Camona Perez <manuel.carm...@wazuh.com> wrote: > Hi Aksha and sorry for the late response, > > I will try to help you solve this issue. I need some information to test > your use case and see what is happening. > > First of all, could you tell me which Wazuh version you are using? Also, > it would be fine if you send the active response script you are trying to > execute. > > In order to troubleshoot this, I recommend that you enable the debug mode > for the *execd* daemon, which is the one in charge of executing active > response scripts. In order to do it, add the following line to > */var/ossec/etc/local_internal_options.conf*: > > > *execd.debug=2* > Waiting for your response! > > On Wednesday, March 2, 2022 at 7:16:14 AM UTC+1 AKSHA GANDHI wrote: > >> Hi Ossec Team, >> >> Can anyone please review this and help. >> >> Thanks in Advance. >> Aksha >> On Friday, February 25, 2022 at 7:17:18 PM UTC+5:30 AKSHA GANDHI wrote: >> >>> Hi, >>> 1. Active response is getting triggered for both Rule ID 550,554 if >>> <expect> parameter is kept blank. 2.If <expect> parameter is given >>> value FILENAME then active response is not getting triggered for RULE ID >>> 554 but is getting triggered for RULE ID 550. 3. Not receiving any >>> error logs. 4. Kindly find the details of the ossec.conf file for which >>> Active response is not getting trigerred for RULE ID 554. >>> >>> ---- ossec.conf ----- >>> <command> <name>Test</name> <executable>syscheck-all.sh</executable> >>> <expect>FILENAME</expect> </command> <active-response> >>> <disabled>no</disabled> <command>Test</command> >>> <location>defined-agent</location> <agent_id>78</agent_id> >>> <rules_id>554,550</rules_id> </active-response> >>> >>> --- ossec.conf --- >>> Please help troubleshot the issue. >>> >>> Thanks & Regards >>> Aksha >>> >> -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to ossec-list+unsubscr...@googlegroups.com. > To view this discussion on the web visit > https://groups.google.com/d/msgid/ossec-list/70ad8924-11df-43cb-a543-5ca4f96a40a0n%40googlegroups.com > <https://groups.google.com/d/msgid/ossec-list/70ad8924-11df-43cb-a543-5ca4f96a40a0n%40googlegroups.com?utm_medium=email&utm_source=footer> > . > -- Disclaimer: Privileged & confidential information is contained in this message (including all attachments). If you are not an intended recipient of this message, please destroy this message immediately and kindly notify the sender by reply e-mail. Any unauthorized use or dissemination of this message in any manner whatsoever, in whole or in part, is strictly prohibited. This e-mail, including all attachments hereto, is for discussion purposes only and shall not be deemed or construed otherwise unless expressly stated. Any views or opinions presented in this email are solely those of the author and do not necessarily represent that of NJ Group of Companies. This communication, including any attachments may not be free of viruses, interceptions or interference, and may not be compatible with your systems. You should carry out your own virus checks before opening any attachment to this e-mail. The sender of this e-mail and NJ Group of Companies shall not be liable for any damage that you may sustain as a result of viruses, incompleteness of this message, a delay in receipt of this message or computer problems experienced. This message has been scanned for viruses and dangerous content by NJGroup Email Server, and is believed to be clean. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/ossec-list/CADrFDiPVGvF8sNGQb3v7CMvATbJqosUX4ctvYXbM8vjk2qGdTA%40mail.gmail.com.