Hi list, I found the following event log from an Ossec Windows agent:
The Windows Firewall has detected an application listening for incoming traffic.
Name: - Path: C:\Program Files\ossec-agent\ossec-agent.exe Process identifier: 2084 User account: SYSTEM User domain: NT AUTHORITY Service: Yes RPC server: No IP version: IPv4 IP protocol: UDP Port number: 3911 Allowed: No User notified: No Do I have to allow the traffic? Rgds. Martin
smime.p7s
Description: S/MIME Cryptographic Signature
