Greetings: We use the <location>all</location> in active-response to block attacks on all agents.
I just noticed there is no /var/ossec/logs/active-responses.log on the ossec server itself. Is there a way to have active-response active on the ossec server so that in that way the ossec server is also treated as an agent? Thank you.
