Hi Annie,
As I can see in the command configuration, you used the
expect option with
srcip. This means that the alert generated that triggered active response must have a
srcip field as the
srcip value will be used in the script.
In the active response configuration, you used the
level option with value
5. This means that all the alerts with level equal or higher than 5 will trigger the active response script.
Taking these 2 statements into account, the following could be happening: an event with level>=5 but without srcip field is being generated, and therefore, the active response script is not being executed. Could you check this?
Also, note that you are using
all in the
location option. This means that the active response script will be executed for all agents when AR is triggered. The
all option should be used with caution because maybe this is not the use case you are looking for. If you use
local, the AR script is executed on the agent that generated the event. If you use
server, the AR script is run on the manager the agent is reporting to. You can find more information about this option
here.