Hi all,
I believe that I found documentation to answer this.  On the master
server, changing location from local to any for each active-response
stanza in ossec.conf will achieve this, correct?

Aaron

On Tue, Nov 30, 2010 at 10:11 AM, Aaron Bliss <[email protected]> wrote:
> Hi all,
> We are successfully using Active Responses against both Windows and
> Linux based hosts.  Currently we are using the boxed null-route and
> firewall-drop responses.  Is it possible to configure the ossec server
> to initiate an active response on all managed agents instead of just
> the agent that triggers a response?  Please advise and thanks.
>
> Aaron
>

Reply via email to