I've also found that you can add noalert="1" to the end of the first
line of the rule if it doesn't have the email alert option and it's
still emailing you:

e.g. <rule id="18119" level="3" noalert="1">

Works for me,

Roch

On 17/04/2008, Rob Skoog <[EMAIL PROTECTED]> wrote:
>
>  Ah,  I didn't realize you could have an override on a per rule basis.
>
>  Thank you,
>
> Rob Skoog
>
>
>  Tim Boyer wrote:
>  >> What I was referring to is that the message has an alert
>  >> level of 3, but the default as I understand it is to only
>  >> send an alert if the even is of a level of 7 or greater?  I'm
>  >> just trying to understand why I was emailed this alert, not
>  >> why it happened.
>  >>
>  >> Thanks,
>  >> Rob Skoog
>  >
>  > Look at the rule:
>  >
>  >   <rule id="18119" level="3">
>  >     <if_sid>18107</if_sid>
>  >     <options>alert_by_email</options>
>  >     <if_fts />
>  >     <description>First time this user logged in this system.</description>
>  >     <group>authentication_success,</group>
>  >   </rule>
>  >
>  > The 'alert_by_email' overrides the default setting.
>  >
>  > -- tim --
>  >
>  >
>  >> ----- Original Message -----
>  >> From: "Kevin Ross" <[EMAIL PROTECTED]>
>  >> To: [email protected]
>  >> Sent: Wednesday, April 16, 2008 6:16:55 PM GMT -05:00
>  >> US/Canada Eastern
>  >> Subject: [ossec-list] Re: Agent email alerts
>  >>
>  >>
>  >> No it monitors authentication successes and failures. This
>  >> sort of thing is to help you spot unauthorised accounts
>  >> created by an attacker. such as suspicious accounts being
>  >> created or someone trying to brute force an account
>  >>
>  >>
>  >>
>  >>
>  >>> Date: Wed, 16 Apr 2008 16:27:07 -0400
>  >>> From: [EMAIL PROTECTED]
>  >>> To: [EMAIL PROTECTED]
>  >>> Subject: [ossec-list] Agent email alerts
>  >>>
>  >>>
>  >>> I'm using the 1.5 beta on a Windows XP box and with a
>  >> CentOS 5 server.
>  >>>
>  >>> I have the email aler loglevel set to the default of 7 and
>  >> I saw the
>  >>> following notification:
>  >>>
>  >>>
>  >>> SUBJECT :OSSEC Notification - (foo) d.d.d.d - Alert level 3
>  >>> OSSEC HIDS Notification.
>  >>> 2008 Apr 16 15:23:43
>  >>>
>  >>> Received From: (foo) 1.1.1.1->WinEvtLog
>  >>> Rule: 18119 fired (level 3) -> "First time this user logged
>  >> in this system."
>  >>> Portion of the log(s):
>  >>>
>  >>> WinEvtLog: Security: AUDIT_SUCCESS(540): Security: SYSTEM:
>  >> NT AUTHORITY:
>  >>> <scrub>: Successful Network Logon: User Name: <scrub> Domain:
>  >>> foo Logon ID: <scrub> Logon Type: 3 Logon Process:
>  >>> Kerberos Authentication Package: Kerberos Workstation Name:
>  >>> Logon GUID: <scrubbed>
>  >>>
>  >>>
>  >>>
>  >>> --END OF NOTIFICATION
>  >>>
>  >>>
>  >>> I'm guessing this is an error?
>  >>>
>  >>> Thanks,
>  >>> Rob
>  >>
>  >> A prize an hour, 24 hours a day. Try Big Snap now!
>  >
>
>

Reply via email to