Not the issue - cmd executes correctly from the ossec-agent install path.
Issue is in parameter list passed from server to agent (2nd param is a
hyphen not the ip address)
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from
When running agent_control from our linux OSSEC server to a specific
windows agent, the agent fails to run the active response. Viewing the
agent in ProcessExplorer, I see the following call to cmd.exe:
C:\Windows\system32\cmd.exe /c ""active-response/bin/block-ip.cmd" add "-" "
192.168.0.101" "