I'm having the same issue with the 1.6 release... Did you ever get this figured out?
Regards, Will On 8/29/08, Wes <[EMAIL PROTECTED]> wrote: > > I was happy to learn that active response is now available for > Windows, but as of yet I've had no luck getting it working. Here's > what I've done so far: > > - Installed 8/28 server snapshot and 8/28 Windows agent snapshot > > - Added the following to ossec.conf on the agent side: > > <active-response> > <disabled>no</disabled> > </active-response> > > - Added the following to ossec.conf on the server side (the goal being > to trigger the active response when any rule level 10 or higher fires, > and block the source IP for 10 minutes): > > <command> > <name>win_nullroute</name> > <executable>route-null.cmd</executable> > <expect>srcip</expect> > <timeout_allowed>yes</timeout_allowed> > </command> > > <active-response> > <command>win_nullroute</command> > <location>local</location> > <level>10</level> > <timeout>600</timeout> > </active-response> > > - Restarted both the server and the agent > > - Checked ossec.log (on the agent) to verify that active response is working: > > 2008/08/29 13:35:29 ossec-execd: INFO: Started (pid: 2772). > > - Tested the active response with: > > # /var/ossec/bin/agent_control -b 2.3.4.5 -f win_nullroute600 -u 011 > > After running the test, the IP 2.3.4.5 shows up when running a 'route > print' on the agent machine. Up until this point, everything appears > to be working fine. > > However, when I send a request to the server that fires a level 12 > false positive (specifically, rule 31106), the alert is logged and I > get the e-mail notification as per usual, but the active response is > not triggered. The IP that I'm sending the test request from does not > get temporarily blocked, nor does anything show up when running a > 'route print'. I've verified that this IP is not whitelisted in > ossec.conf. > > Any ideas what I might be doing wrong? Thanks! >
