Greetings:

Looking at the files in the active-response/bin directory I noticed
they are owned by root, and group owned by ossec.

Is your file group owned by ossec?

I also noticed that every one had "#!/bin/sh" at the start, and /bin/
sh was present in the file system as a valid shell.

Our active-response works, so I know overall yours should work too,
but it may require some tweaking.

Thank you.

Reply via email to