Thank you very much for your answer.

I have modified my ossec.conf following yours advices. I have alerts
(seen in /var/ossec/logs/ossec.log on server) but no active-response
(seen in /var/ossec/logs/active-response.log on the agent).

I wonder what is the usage of
<location>defined-agent</location>
<agent_id>#agent</agent_id>

Thank you for your help.

Best regards.


On 15 oct, 15:56, "dan (ddp)" <[email protected]> wrote:
> On Sun, Oct 10, 2010 at 9:48 AM, tux3132 <[email protected]> wrote:
> > I
>
> > I have installed OSSEC 2.5 on Debian Lenny and all is working fine.
>
> > I have created a command :
>
> >  <command>
> >    <name>firewall_drop</name>
> >    <executable>firewall-drop.sh</executable>
> >    <expect>srcip</expect>
> >    <timeout_allowed>yes</timeout_allowed>
> >  </command>
>
> > and two active-response, one for each agents 007 (its name is
> > James ...lol) and 008. All parameters are identical but <agent_id>...</
> > agent_id>
> > agent 007
> >  <active-response>
> >    <command>firewall_drop</command>
> >    <location>defined-agent</location>
> >    <agent_id>007</agent_id>
>
> > <rules_id>3301,3302,3303,3304,3305,3306,3351,3352,3353,3354,3355,3356,3357,</
> > rules_id>
> >    <timeout>3610</timeout>
> >  </active-response>
> > agent 008
> >  <active-response>
> >    <command>firewall_drop</command>
> >    <location>defined-agent</location>
> >    <agent_id>008</agent_id>
>
> > <rules_id>3301,3302,3303,3304,3305,3306,3351,3352,3353,3354,3355,3356,3357,</
> > rules_id>
> >    <timeout>3610</timeout>
> >  </active-response>
>
> > When, for example, the rule 3306 is fired up by the agent 007 the
> > script firewall-drop.sh is ran on its host and is also ran on the
> > other host where agent 008 reside.
>
> > Obviously in this case of spam it is not really a problem because an
> > active spammer is blacklisted even on a machine where it is not
> > active ... But for some other kinds of responses it may become a
> > problem.
>
> > Have-I understood the OSSEC principle and/or syntax ?
> > Have-you encountered this problem and how do you solve it ?
>
> > Thank you for your help.
>
> > Best regards.
>
> It's doing what you asked. You told it that if rule (example) 3301
> fires run it on 0007. Then run the script on 008. It sounds like that
> is what is happening.
> If you want only 007 to run the script when the event happens on 007
> use <location>local</location>. 
> Seehttp://www.ossec.net/doc/manual/ar/ar-unix.htmlfor more information.
>
> Otherwise, if you're worried, you'll have to be careful which rules
> you add into these configurations.

Reply via email to