Skip to content

Clarify active-response expect fields and fixed script argv. - #358

Merged
atomicturtle merged 3 commits into
ossec:masterfrom
atomicturtle:docs/2104-ar-expect-placeholders
Aug 4, 2026
Merged

Clarify active-response expect fields and fixed script argv.#358
atomicturtle merged 3 commits into
ossec:masterfrom
atomicturtle:docs/2104-ar-expect-placeholders

Conversation

@atomicturtle

Copy link
Copy Markdown
Member

Document that expect selects srcip/user/username/filename without reordering arguments, and add an FAQ for the common add/- confusion.

Document that expect selects srcip/user/username/filename without
reordering arguments, and add an FAQ for the common add/- confusion.
The file was ISO-8859-1; Python 3.12 Sphinx failed with UnicodeDecodeError
on byte 0xa4 while building HTML.
@atomicturtle
atomicturtle merged commit 88abf0c into ossec:master Aug 4, 2026
1 check passed
@atomicturtle
atomicturtle deleted the docs/2104-ar-expect-placeholders branch August 5, 2026 17:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant