As a complement when on the server I run agent-control -R agent_id on
the client I have infos in active-response.log

When I have created the client (manage-agent) I have specified "any"
for the IP address of the client.

Maybe it can have some importance ?

Anticipated thanks.

Best regards.

On 15 oct, 18:04, tux3132 <[email protected]> wrote:
> Thank you very much for your answer.
>
> I have modified my ossec.conf following yours advices. I have alerts
> (seen in /var/ossec/logs/ossec.log on server) but no active-response
> (seen in /var/ossec/logs/active-response.log on the agent).
>
> I wonder what is the usage of
> <location>defined-agent</location>
> <agent_id>#agent</agent_id>
>
> Thank you for your help.
>
> Best regards.
>
> On 15 oct, 15:56, "dan (ddp)" <[email protected]> wrote:
>
> > On Sun, Oct 10, 2010 at 9:48 AM, tux3132 <[email protected]> wrote:
> > > I
>
> > > I have installed OSSEC 2.5 on Debian Lenny and all is working fine.
>
> > > I have created a command :
>
> > >  <command>
> > >    <name>firewall_drop</name>
> > >    <executable>firewall-drop.sh</executable>
> > >    <expect>srcip</expect>
> > >    <timeout_allowed>yes</timeout_allowed>
> > >  </command>
>
> > > and two active-response, one for each agents 007 (its name is
> > > James ...lol) and 008. All parameters are identical but <agent_id>...</
> > > agent_id>
> > > agent 007
> > >  <active-response>
> > >    <command>firewall_drop</command>
> > >    <location>defined-agent</location>
> > >    <agent_id>007</agent_id>
>
> > > <rules_id>3301,3302,3303,3304,3305,3306,3351,3352,3353,3354,3355,3356,3357,</
> > > rules_id>
> > >    <timeout>3610</timeout>
> > >  </active-response>
> > > agent 008
> > >  <active-response>
> > >    <command>firewall_drop</command>
> > >    <location>defined-agent</location>
> > >    <agent_id>008</agent_id>
>
> > > <rules_id>3301,3302,3303,3304,3305,3306,3351,3352,3353,3354,3355,3356,3357,</
> > > rules_id>
> > >    <timeout>3610</timeout>
> > >  </active-response>
>
> > > When, for example, the rule 3306 is fired up by the agent 007 the
> > > script firewall-drop.sh is ran on its host and is also ran on the
> > > other host where agent 008 reside.
>
> > > Obviously in this case of spam it is not really a problem because an
> > > active spammer is blacklisted even on a machine where it is not
> > > active ... But for some other kinds of responses it may become a
> > > problem.
>
> > > Have-I understood the OSSEC principle and/or syntax ?
> > > Have-you encountered this problem and how do you solve it ?
>
> > > Thank you for your help.
>
> > > Best regards.
>
> > It's doing what you asked. You told it that if rule (example) 3301
> > fires run it on 0007. Then run the script on 008. It sounds like that
> > is what is happening.
> > If you want only 007 to run the script when the event happens on 007
> > use <location>local</location>. 
> > Seehttp://www.ossec.net/doc/manual/ar/ar-unix.htmlformore information.
>
> > Otherwise, if you're worried, you'll have to be careful which rules
> > you add into these configurations.

Reply via email to