Anything in the logs? Maybe /var/ossec/logs/ossec.log? Are the scripts in place and executable? Have you tried running one of the scripts to see if it works on that system?
On Thu, May 6, 2010 at 4:20 PM, tm <[email protected]> wrote: > Hello, > > I have the location set to "all" in the firewall-drop and host-deny > active responses in the ossec.conf file on the OSSEC server. If I > simulate an attack on one of the OSSEC agent hosts, both responses are > working on all the OSSEC agents but not on the OSSEC server. > > Any ideas? > > Thanks, > Trevor >
