I would make sure ar.conf is getting passed back to the agents. At the same 
time, is merged.mg being updated?

That was always the problem I found when AR stopped working.
~J


On Tuesday, January 20, 2015 at 1:47:30 AM UTC-8, Thomas Vidal wrote:
>
> Dear all,
>
> Active response stop working one month ago and I really don't understand 
> what's the problem is !
>
> On Ossec server, rules are fired when I copy paste a log line in 
> ossec-logtest, and rules are working on the server (shown on WebGui and in 
> server log)
> I can also send an active response to ossec client by using agent_control, 
> and client add the IP to IPTABLES.
>
> But when the rule is fired on the server the clients didn't get the 
> information...
>
> Do you know how I can debug this ??
>
> Many thanks for your help.
>
> Thomas
>
>
>
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to