What I ended up doing was making a custom rule:
<!-- stop email spam from windows -->
<rule id="118119" level="3">
<if_sid>18119</if_sid>
<options>no_email_alert</options>
<if_fts />
<description>First time this user logged in this system.</description>
<group>authentication_success,</group>
</rule>
I've read through the docs some but does anyone know if it is possible
to classify the hosts and base rules on that... for instance I would
love that rule to only override if the machine is a windows workstation.
Thanks,
Rob Skoog
Roch wrote:
> I've also found that you can add noalert="1" to the end of the first
> line of the rule if it doesn't have the email alert option and it's
> still emailing you:
>
> e.g. <rule id="18119" level="3" noalert="1">
>
> Works for me,
>
> Roch
>
> On 17/04/2008, Rob Skoog <[EMAIL PROTECTED]> wrote:
>> Ah, I didn't realize you could have an override on a per rule basis.
>>
>> Thank you,
>>
>> Rob Skoog
>>
>>
>> Tim Boyer wrote:
>> >> What I was referring to is that the message has an alert
>> >> level of 3, but the default as I understand it is to only
>> >> send an alert if the even is of a level of 7 or greater? I'm
>> >> just trying to understand why I was emailed this alert, not
>> >> why it happened.
>> >>
>> >> Thanks,
>> >> Rob Skoog
>> >
>> > Look at the rule:
>> >
>> > <rule id="18119" level="3">
>> > <if_sid>18107</if_sid>
>> > <options>alert_by_email</options>
>> > <if_fts />
>> > <description>First time this user logged in this system.</description>
>> > <group>authentication_success,</group>
>> > </rule>
>> >
>> > The 'alert_by_email' overrides the default setting.
>> >
>> > -- tim --
>> >
>> >
>> >> ----- Original Message -----
>> >> From: "Kevin Ross" <[EMAIL PROTECTED]>
>> >> To: [email protected]
>> >> Sent: Wednesday, April 16, 2008 6:16:55 PM GMT -05:00
>> >> US/Canada Eastern
>> >> Subject: [ossec-list] Re: Agent email alerts
>> >>
>> >>
>> >> No it monitors authentication successes and failures. This
>> >> sort of thing is to help you spot unauthorised accounts
>> >> created by an attacker. such as suspicious accounts being
>> >> created or someone trying to brute force an account
>> >>
>> >>
>> >>
>> >>
>> >>> Date: Wed, 16 Apr 2008 16:27:07 -0400
>> >>> From: [EMAIL PROTECTED]
>> >>> To: [EMAIL PROTECTED]
>> >>> Subject: [ossec-list] Agent email alerts
>> >>>
>> >>>
>> >>> I'm using the 1.5 beta on a Windows XP box and with a
>> >> CentOS 5 server.
>> >>>
>> >>> I have the email aler loglevel set to the default of 7 and
>> >> I saw the
>> >>> following notification:
>> >>>
>> >>>
>> >>> SUBJECT :OSSEC Notification - (foo) d.d.d.d - Alert level 3
>> >>> OSSEC HIDS Notification.
>> >>> 2008 Apr 16 15:23:43
>> >>>
>> >>> Received From: (foo) 1.1.1.1->WinEvtLog
>> >>> Rule: 18119 fired (level 3) -> "First time this user logged
>> >> in this system."
>> >>> Portion of the log(s):
>> >>>
>> >>> WinEvtLog: Security: AUDIT_SUCCESS(540): Security: SYSTEM:
>> >> NT AUTHORITY:
>> >>> <scrub>: Successful Network Logon: User Name: <scrub> Domain:
>> >>> foo Logon ID: <scrub> Logon Type: 3 Logon Process:
>> >>> Kerberos Authentication Package: Kerberos Workstation Name:
>> >>> Logon GUID: <scrubbed>
>> >>>
>> >>>
>> >>>
>> >>> --END OF NOTIFICATION
>> >>>
>> >>>
>> >>> I'm guessing this is an error?
>> >>>
>> >>> Thanks,
>> >>> Rob
>> >>
>> >> A prize an hour, 24 hours a day. Try Big Snap now!
>> >
>>
>>