Kevin Reiter wrote:
: List Subscriptions wrote:
:: Hey Kevin,
:: 
:: The reason your rule isn't working is because Snort02/Snort02 is
:: decoded as the hostname and not part of the log message (<match> is
:: used only for the log message).  Something like this would work:
:: 
:: <rule id="103004" level="0">
::    <if_sid>5104</if_sid>
::    <hostname>Snort02/Snort02</hostname>
::    <description>Interface (xl0) entered promiscuous mode on
::  Snort02</description> </rule>
:: 
:: Upgrading to the latest snapshot will get you the amazing
:: ossec-logtest which is perfect for these situations.
: 
: 
: Where is it?  I just downloaded/installed the snapshot from yesterday
: (ossec-hids-080820.tar.gz) and it isn't there.  Any idea which
: snapshot it's contained in?  I REALLY want to play with that :)  
 
Nevermind - found it..
 
:: 2008/08/20 11:48:13 ossec-testrule: INFO: Started (pid: 21847).
:: ossec-testrule: Type one log per line.
:: 
:: Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode enabled
:: 
:: 
:: **Phase 1: Completed pre-decoding.
::        full event: 'Aug 20 09:39:49 Snort02/Snort02 kernel: xl0:
::        promiscuous mode enabled' hostname: 'Snort02/Snort02'
::        program_name: 'kernel'
::        log: 'xl0: promiscuous mode enabled'
:: 
:: **Phase 2: Completed decoding.
::        decoder: 'iptables'
:: 
:: **Phase 3: Completed filtering (rules).
::        Rule id: '103004'
::        Level: '0'
::        Description: 'Interface (xl0) entered promiscuous mode on
:: Snort02' 
:: 
:: 
:: Cheers,
:: 
:: cnk
:: 
:: 
:: 
:: On Wed, Aug 20, 2008 at 9:57 AM, Kevin Reiter <[EMAIL PROTECTED]>
:: wrote:
::: 
::: Hello list,
::: 
::: I'm trying to stop sending an e-mail alert when a rule fires and
::: certain criteria are matched, as per
::: 
http://www.ossec.net/wiki/index.php/Know_How:Ignore_Rules#Ignoring_syslog_message
::: 
::: Here's the alert I'm currently receiving:
::: 
::: Received From: Snort02/Snort02->/path/to/snort.log
::: Rule: 5104 fired (level 8) -> "Interface entered in
::: promiscuous(sniffing) mode." Portion of the log(s):
::: 
::: Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode
::: enabled 
::: 
::: I'm restarting Snort every hour, which means I'm getting the above
::: e-mail alert every hour.  I've added the following rule to
::: local_rules.xml: 
::: 
::: <!-- Ignore Snort02 going into promisc mode -->
::: 
:::  <rule id="103004" level="0">
:::    <if_sid>5104</if_sid>
:::    <match>Snort02</match>
:::    <description>Interface (xl0) entered promiscuous mode on
::: Snort02</description>  </rule>
::: 
::: I then restarted the OSSEC server, gave it a minute, then restarted
::: Snort, and I still get the e-mail alert.
::: 
::: Is there something wrong with my syntax?  I'm running 1.4 (yes, I
::: know, I need to upgrade :) 
::: 
::: 
::: Thanks,
::: Kevin
::: 
::: This message may contain confidential or proprietary information and
::: is intended solely for the individual(s) to whom it is addressed.
::: If you are not a named addressee you should not disseminate,
::: distribute or copy this e-mail or act upon the information contained
::: herein.  Please notify the sender immediately by e-mail if you have
::: received this e-mail by mistake and delete this e-mail from your
::: system.

Reply via email to