Hi all, I believe that I found documentation to answer this. On the master server, changing location from local to any for each active-response stanza in ossec.conf will achieve this, correct?
Aaron On Tue, Nov 30, 2010 at 10:11 AM, Aaron Bliss <[email protected]> wrote: > Hi all, > We are successfully using Active Responses against both Windows and > Linux based hosts. Currently we are using the boxed null-route and > firewall-drop responses. Is it possible to configure the ossec server > to initiate an active response on all managed agents instead of just > the agent that triggers a response? Please advise and thanks. > > Aaron >
