Ah,  I didn't realize you could have an override on a per rule basis.

Thank you,
Rob Skoog

Tim Boyer wrote:
>> What I was referring to is that the message has an alert 
>> level of 3, but the default as I understand it is to only 
>> send an alert if the even is of a level of 7 or greater?  I'm 
>> just trying to understand why I was emailed this alert, not 
>> why it happened.
>>
>> Thanks,
>> Rob Skoog
> 
> Look at the rule:
> 
>   <rule id="18119" level="3">
>     <if_sid>18107</if_sid>
>     <options>alert_by_email</options>
>     <if_fts />
>     <description>First time this user logged in this system.</description>
>     <group>authentication_success,</group>
>   </rule>
> 
> The 'alert_by_email' overrides the default setting.
> 
> -- tim -- 
> 
> 
>> ----- Original Message -----
>> From: "Kevin Ross" <[EMAIL PROTECTED]>
>> To: [email protected]
>> Sent: Wednesday, April 16, 2008 6:16:55 PM GMT -05:00 
>> US/Canada Eastern
>> Subject: [ossec-list] Re: Agent email alerts
>>
>>
>> No it monitors authentication successes and failures. This 
>> sort of thing is to help you spot unauthorised accounts 
>> created by an attacker. such as suspicious accounts being 
>> created or someone trying to brute force an account 
>>
>>
>>
>>
>>> Date: Wed, 16 Apr 2008 16:27:07 -0400 
>>> From: [EMAIL PROTECTED] 
>>> To: [EMAIL PROTECTED] 
>>> Subject: [ossec-list] Agent email alerts 
>>>
>>>
>>> I'm using the 1.5 beta on a Windows XP box and with a 
>> CentOS 5 server. 
>>>
>>> I have the email aler loglevel set to the default of 7 and 
>> I saw the 
>>> following notification: 
>>>
>>>
>>> SUBJECT :OSSEC Notification - (foo) d.d.d.d - Alert level 3 
>>> OSSEC HIDS Notification. 
>>> 2008 Apr 16 15:23:43 
>>>
>>> Received From: (foo) 1.1.1.1->WinEvtLog 
>>> Rule: 18119 fired (level 3) -> "First time this user logged 
>> in this system." 
>>> Portion of the log(s): 
>>>
>>> WinEvtLog: Security: AUDIT_SUCCESS(540): Security: SYSTEM: 
>> NT AUTHORITY: 
>>> <scrub>: Successful Network Logon: User Name: <scrub> Domain: 
>>> foo Logon ID: <scrub> Logon Type: 3 Logon Process: 
>>> Kerberos Authentication Package: Kerberos Workstation Name: 
>>> Logon GUID: <scrubbed> 
>>>
>>>
>>>
>>> --END OF NOTIFICATION 
>>>
>>>
>>> I'm guessing this is an error? 
>>>
>>> Thanks, 
>>> Rob 
>>
>> A prize an hour, 24 hours a day. Try Big Snap now! 
> 

Reply via email to