List Subscriptions wrote:
: Hey Kevin,
: 
: The reason your rule isn't working is because Snort02/Snort02 is
: decoded as the hostname and not part of the log message (<match> is
: used only for the log message).  Something like this would work:
: 
: <rule id="103004" level="0">
:    <if_sid>5104</if_sid>
:    <hostname>Snort02/Snort02</hostname>
:    <description>Interface (xl0) entered promiscuous mode on
: Snort02</description>
:  </rule>
: 
: Upgrading to the latest snapshot will get you the amazing
: ossec-logtest which is perfect for these situations.


Where is it?  I just downloaded/installed the snapshot from yesterday 
(ossec-hids-080820.tar.gz) and it isn't there.  Any idea which snapshot it's 
contained in?  I REALLY want to play with that :)

 
: 2008/08/20 11:48:13 ossec-testrule: INFO: Started (pid: 21847).
: ossec-testrule: Type one log per line.
: 
: Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode enabled
: 
: 
: **Phase 1: Completed pre-decoding.
:        full event: 'Aug 20 09:39:49 Snort02/Snort02 kernel: xl0:
: promiscuous mode enabled'
:        hostname: 'Snort02/Snort02'
:        program_name: 'kernel'
:        log: 'xl0: promiscuous mode enabled'
: 
: **Phase 2: Completed decoding.
:        decoder: 'iptables'
: 
: **Phase 3: Completed filtering (rules).
:        Rule id: '103004'
:        Level: '0'
:        Description: 'Interface (xl0) entered promiscuous mode on
: Snort02' 
: 
: 
: Cheers,
: 
: cnk
: 
: 
: 
: On Wed, Aug 20, 2008 at 9:57 AM, Kevin Reiter <[EMAIL PROTECTED]>
: wrote: 
:: 
:: Hello list,
:: 
:: I'm trying to stop sending an e-mail alert when a rule fires and
:: certain criteria are matched, as per
:: 
http://www.ossec.net/wiki/index.php/Know_How:Ignore_Rules#Ignoring_syslog_message
:: 
:: Here's the alert I'm currently receiving:
:: 
:: Received From: Snort02/Snort02->/path/to/snort.log
:: Rule: 5104 fired (level 8) -> "Interface entered in
:: promiscuous(sniffing) mode." 
:: Portion of the log(s):
:: 
:: Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode enabled
:: 
:: I'm restarting Snort every hour, which means I'm getting the above
:: e-mail alert every hour.  I've added the following rule to
:: local_rules.xml:  
:: 
:: <!-- Ignore Snort02 going into promisc mode -->
:: 
::  <rule id="103004" level="0">
::    <if_sid>5104</if_sid>
::    <match>Snort02</match>
::    <description>Interface (xl0) entered promiscuous mode on
:: Snort02</description>  </rule> 
:: 
:: I then restarted the OSSEC server, gave it a minute, then restarted
:: Snort, and I still get the e-mail alert. 
:: 
:: Is there something wrong with my syntax?  I'm running 1.4 (yes, I
:: know, I need to upgrade :) 
:: 
:: 
:: Thanks,
:: Kevin
:: 
:: This message may contain confidential or proprietary information and
:: is intended solely for the individual(s) to whom it is addressed. 
:: If you are not a named addressee you should not disseminate,
:: distribute or copy this e-mail or act upon the information contained
:: herein.  Please notify the sender immediately by e-mail if you have
:: received this e-mail by mistake and delete this e-mail from your
:: system.      

Reply via email to