-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Active response doesn't work #2134
Comments
https://documentation.wazuh.com/current/compliance/pci-dss/active-response.html I use block of code in this link to conf (The github doesn't allow me to paste code ) |
Hello, could you share your active-response section from your configuration file? Here's an example that I use without any issues. Also make sure that the machine you're testing from isn't included within the <allow_list> as it would not be affected by the active response https://ossec-documentation.readthedocs.io/en/latest/configuration/ossec_conf.html#allow-list
|
I am setting up some rules to test the ossec server attacked by flood syn from kali linux.
I have configure some rules in ossec.conf to help it defense when being attacked:
The active response litterally doesn't work, it doesn't alert sshd authentication fail or anything, and the server is litterally being attacked without any alert to me.
Any solutions to this problem? Appreciate for your replies.
The text was updated successfully, but these errors were encountered: