Hi Peter, Just changing the config to the following should to it:
<location>all|server</location> Hope it helps. -- Daniel B. Cid dcid ( at ) ossec.net On Nov 28, 2007 2:26 PM, Peter M. Abraham <[EMAIL PROTECTED]> wrote: > > Greetings: > > We use the <location>all</location> in active-response to block > attacks on all agents. > > I just noticed there is no /var/ossec/logs/active-responses.log on the > ossec server itself. > > Is there a way to have active-response active on the ossec server so > that in that way the ossec server is also treated as an agent? > > Thank you. >