Hello Folks,

Once in a while, the active response does not kick in. Then I have to
go into /var/ossec/queue/rids of the OSSEC agent host and to delete
the agent ID file, say "011", and restart OSSEC at the agent. And I
have to go into/var/ossec/queue/rids of the OSSEC server host, delete
the agent ID file there - in this case, "011", and restart OSSEC at
the server. At which point, active response will kick in if the
appropriate rule is triggered through the agent's syslog.

My question is "why do I have to this house cleaning"? It is as if the
lines of communication between OSSEC server and OSSEC agent that
pertain to active response just went dead, and I have to compel the
OSSEC agent and OSSEC server to shake hands again.

Reply via email to