Makes sense...just wanted to make sure there wasn't an easier way already
built into ossec that I'd just need to modify the ossec.conf file to
initiate.  Thanks for the quick response!

On Tue, Feb 8, 2011 at 11:51 AM, dan (ddp) <[email protected]> wrote:

> Hi James,
>
> On Tue, Feb 8, 2011 at 2:07 PM, James Ford <[email protected]> wrote:
> > I can't seem to find in the documentation anywhere about the ability to
> > email when Active Response executes a block on IP or when it would drop
> it.
> > I know you can see the block message in the Active Response log, so is
> there
> > a way to email those messages as well?  Maybe I'm missing something or
> > someone out there has already done this.  I can't imagine I'm the first
> to
> > ask about it, yet I can't seem to find anything on it anywhere.  Anyone
> > doing this?  Thanks!
> >
>
> Monitor the active response log file with ossec, and create rules for
> the various log messages.
> Or modify the AR scripts to mail you when they're run.
>

Reply via email to