Hello, I have the location set to "all" in the firewall-drop and host-deny active responses in the ossec.conf file on the OSSEC server. If I simulate an attack on one of the OSSEC agent hosts, both responses are working on all the OSSEC agents but not on the OSSEC server.
Any ideas? Thanks, Trevor
