List Subscriptions wrote:
: Hey Kevin,
:
: The reason your rule isn't working is because Snort02/Snort02 is
: decoded as the hostname and not part of the log message (<match> is
: used only for the log message). Something like this would work:
:
: <rule id="103004" level="0">
: <if_sid>5104</if_sid>
: <hostname>Snort02/Snort02</hostname>
: <description>Interface (xl0) entered promiscuous mode on
: Snort02</description>
: </rule>
Thanks, tried that:
<rule id="103004" level="0">
<if_sid>5104</if_sid>
<hostname>Snort02/Snort02</hostname>
<program_name>kernel</program_name>
<description>Interface (xl0) entered promiscuous mode on
Snort02</description>
</rule>
Still get the alerts :/
: Upgrading to the latest snapshot will get you the amazing
: ossec-logtest which is perfect for these situations.
I'll probably do that later today or tomorrow.
Thanks!
: 2008/08/20 11:48:13 ossec-testrule: INFO: Started (pid: 21847).
: ossec-testrule: Type one log per line.
:
: Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode enabled
:
:
: **Phase 1: Completed pre-decoding.
: full event: 'Aug 20 09:39:49 Snort02/Snort02 kernel: xl0:
: promiscuous mode enabled'
: hostname: 'Snort02/Snort02'
: program_name: 'kernel'
: log: 'xl0: promiscuous mode enabled'
:
: **Phase 2: Completed decoding.
: decoder: 'iptables'
:
: **Phase 3: Completed filtering (rules).
: Rule id: '103004'
: Level: '0'
: Description: 'Interface (xl0) entered promiscuous mode on
: Snort02'
:
:
: Cheers,
:
: cnk
:
:
:
: On Wed, Aug 20, 2008 at 9:57 AM, Kevin Reiter <[EMAIL PROTECTED]>
: wrote:
::
:: Hello list,
::
:: I'm trying to stop sending an e-mail alert when a rule fires and
:: certain criteria are matched, as per
::
http://www.ossec.net/wiki/index.php/Know_How:Ignore_Rules#Ignoring_syslog_message
::
:: Here's the alert I'm currently receiving:
::
:: Received From: Snort02/Snort02->/path/to/snort.log
:: Rule: 5104 fired (level 8) -> "Interface entered in
:: promiscuous(sniffing) mode."
:: Portion of the log(s):
::
:: Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode enabled
::
:: I'm restarting Snort every hour, which means I'm getting the above
:: e-mail alert every hour. I've added the following rule to
:: local_rules.xml:
::
:: <!-- Ignore Snort02 going into promisc mode -->
::
:: <rule id="103004" level="0">
:: <if_sid>5104</if_sid>
:: <match>Snort02</match>
:: <description>Interface (xl0) entered promiscuous mode on
:: Snort02</description> </rule>
::
:: I then restarted the OSSEC server, gave it a minute, then restarted
:: Snort, and I still get the e-mail alert.
::
:: Is there something wrong with my syntax? I'm running 1.4 (yes, I
:: know, I need to upgrade :)
::
::
:: Thanks,
:: Kevin
::
:: This message may contain confidential or proprietary information and
:: is intended solely for the individual(s) to whom it is addressed.
:: If you are not a named addressee you should not disseminate,
:: distribute or copy this e-mail or act upon the information contained
:: herein. Please notify the sender immediately by e-mail if you have
:: received this e-mail by mistake and delete this e-mail from your
:: system.