Hello Folks, Once in a while, the active response does not kick in. Then I have to go into /var/ossec/queue/rids of the OSSEC agent host and to delete the agent ID file, say "011", and restart OSSEC at the agent. And I have to go into/var/ossec/queue/rids of the OSSEC server host, delete the agent ID file there - in this case, "011", and restart OSSEC at the server. At which point, active response will kick in if the appropriate rule is triggered through the agent's syslog.
My question is "why do I have to this house cleaning"? It is as if the lines of communication between OSSEC server and OSSEC agent that pertain to active response just went dead, and I have to compel the OSSEC agent and OSSEC server to shake hands again.
