Greetings:

We use the <location>all</location> in active-response to block
attacks on all agents.

I just noticed there is no /var/ossec/logs/active-responses.log on the
ossec server itself.

Is there a way to have active-response active on the ossec server so
that in that way the ossec server is also treated as an agent?

Thank you.

Reply via email to