Anything in the logs? Maybe /var/ossec/logs/ossec.log?
Are the scripts in place and executable?
Have you tried running one of the scripts to see if it works on that system?

On Thu, May 6, 2010 at 4:20 PM, tm <[email protected]> wrote:
> Hello,
>
> I have the location set to "all" in the firewall-drop and host-deny
> active responses in the ossec.conf file on the OSSEC server.  If I
> simulate an attack on one of the OSSEC agent hosts, both responses are
> working on all the OSSEC agents but not on the OSSEC server.
>
> Any ideas?
>
> Thanks,
> Trevor
>

Reply via email to