Good afternoon Cedrick,
I was following the article about the scheduled task , and I have set and everything on Wazuh side and sysmon on the server, but it does not work. The event even does not appear on the Wazuh dashboard when I schedule the task on the server with command line.
I have manually added the "C:\Program Files (x86)\ossec-agent\active-response\bin\analyze-scheduled-task.cmd"
specifically "analyze.schedulred-task.cmd" based on this path. Should it be generated automatically or I do need do add it manually?
Also, the when I test the the functionality with creating a scheduled task though this command "schtasks /create /tn test-task /tr "C:\Windows\System32\calc.exe" /sc onlogon /ru System /f"
the active response log is not generated automatically here "C:\Program Files (x86)\ossec-agent\logs\scheduled-tasks.log".
I tried to add it manually and again it does not work.
Can you please advise what could be the potential issue?
Thank you,
Daria