1. Active response is getting triggered for both Rule ID 550,554 if <expect> parameter is kept blank.
2. If <expect> parameter is given value FILENAME then active response is not getting triggered for RULE ID 554 but is getting triggered for RULE ID 550.
3. Not receiving any error logs.
4. Kindly find the details of the ossec.conf file for which Active response is not getting trigerred for RULE ID 554
<command>
<name>Test</name>
<executable>syscheck-all.sh</executable>
<expect>FILENAME</expect>
</command>
<active-response>
<disabled>no</disabled>
<command>Test</command>
<location>defined-agent</location>
<agent_id>78</agent_id>
<rules_id>554,550</rules_id>
</active-response>
Request to help trouble shoot the issue.