Hi Nicolas
I got this to work by using the following:
ossec.conf:
<active-response>
<command>ufw-restart</command>
<location>local</location>
<rules_id>200007</rules_id>
</active-response>
<localfile>
<log_format>command</log_format>
<command>ufw status</command>
<frequency>360</frequency>
</localfile>
local_rules.xml:
<rule id="200007" level="12">
<if_sid>530</if_sid>
<match>ossec: output: 'ufw status'</match>
<regex>inactive</regex>
<description>Monitor UFW</description>
<group>process_monitor,</group>
</rule>
/var/ossec/active-response/bin/ufw-restart:
#!/bin/bash
/usr/sbin/ufw enable
Thanks.