Hi,

Your fix work very good.

Thank you very much ;)

Daniel Cid escribió:
> Hi,
>
> The reason why it is not working is because OSSEC pre-decodes the
> syslog fields, so
> your regex is not matching it.
>
> If you look at the log-test tool, it says:
>
>
> **Phase 1: Completed pre-decoding.
>        full event: 'Jul 10 16:13:14 name/1.2.3.4 lighttpd[30734]:
> 3.4.5.6 www.lala.com - [10/Jul/2008:16:13:14 +0200] "GET /dsgdfgd
> HTTP/1.0" 404 345 "-" "Wget/1.11.1" "-"'
>        hostname: 'name/1.2.3.4'
>        program_name: 'lighttpd'
>        log: '3.4.5.6 www.lala.com - [10/Jul/2008:16:13:14 +0200] "GET
> /dsgdfgd HTTP/1.0" 404 345 "-" "Wget/1.11.1" "-"'
>
> **Phase 2: Completed decoding.
>        No decoder matched.
>
>
> So, if you change your decoder to:
>
> <decoder name="lighttpd-syslog-ng">
>  <type>web-log</type>
>  <program_name>^lighttpd</program_name>
>  <regex>^(\d+.\d+.\d+.\d+) \S+ \S+ [\S+ \S+] \S+ (\S+) HTTP\S+ (\d+) </regex>
>  <order>srcip, url, id</order>
> </decoder>
>
>
> It should work.. Running the same log-test tool, you get:
>
>
> **Phase 1: Completed pre-decoding.
>        full event: 'Jul 10 16:13:14 name/1.2.3.4 lighttpd[30734]:
> 3.4.5.6 www.lala.com - [10/Jul/2008:16:13:14 +0200] "GET /dsgdfgd
> HTTP/1.0" 404 345 "-" "Wget/1.11.1" "-"'
>        hostname: 'name/1.2.3.4'
>        program_name: 'lighttpd'
>        log: '3.4.5.6 www.lala.com - [10/Jul/2008:16:13:14 +0200] "GET
> /dsgdfgd HTTP/1.0" 404 345 "-" "Wget/1.11.1" "-"'
>
> **Phase 2: Completed decoding.
>        decoder: 'lighttpd-syslog-ng'
>        srcip: '3.4.5.6'
>        url: '/dsgdfgd'
>        id: '404'
>
> **Phase 3: Completed filtering (rules).
>        Rule id: '31101'
>        Level: '5'
>        Description: 'Web server 400 error code.'
> **Alert to be generated.
>
>
> Hope it helps.
>
>
> --
> Daniel B. Cid
> dcid ( at ) ossec.net
>
> On Thu, Jul 10, 2008 at 11:29 AM, DeuS <[EMAIL PROTECTED]> wrote:
>   
>> Hello everybody,
>>
>> I have a Syslog-ng remote log server. In this server i'm installed OSSEC
>> 1.5.1 server, but i have problems with lighttpd (like apache combined
>> logs). Syslog add header for each log line:
>>
>> Jul 10 16:13:14 name/x.x.x.x lighttpd[30734]: XXX.X.XXX.X www.XXXX.XXXX
>> - [10/Jul/2008:16:13:14 +0200] "GET /dsgdfgd HTTP/1.0" 404 345 "-"
>> "Wget/1.11.1" "-"
>>
>>
>> test: perl -e 'for($i=0;$i<50;$i++){ system("wget
>> \"http://www.XXXXX.XXXX/dsgdfgd\"";); }'
>>
>>
>> I added to ossec.conf:
>>
>>  <localfile>
>>    <log_format>apache</log_format>
>>    <location>/var/ossec/etc/logfiles/access.log</location>
>>  </localfile>
>>
>> I have <log_format>apache</log_format> but debug mode say: 2008/07/10
>> 16:13:14 ossec-logcollector: DEBUG: Reading syslog message: 'Jul 10
>> 16:13:14 name/x.x.x.x lighttpd[30734]:
>>
>> decoder.xml:
>>
>> <decoder name="lighttpd-syslog-ng">
>>  <type>web-log</type>
>>  <prematch>^\S+ \d+ \S+ \S+ \S+ \d+.\d+.\d+.\d+ </prematch>
>>  <regex>^\S+ \d+ \S+ \S+ \S+ (\d+.\d+.\d+.\d+) \S+ \S+ [\S+ \S\d+] </regex>
>>  <regex>"\w+ (\S+) HTTP\S+ (\d+) </regex>
>>  <order>srcip, url, id</order>
>> </decoder>
>>
>> local_rules.xml
>>
>> <rule id="110001" level="10">
>>   <decoded_as>lighttpd-syslog-ng</decoded_as>
>>   <description>Lighttpd</description>
>> </rule>
>>
>> Where is the problem?
>>
>> Thanks.
>>
>>
>>
>>     


Reply via email to