You need to compile logtest as outlined in this blog post:

http://www.ossec.net/dcid/?p=136

Cheers,

cnk

On Thu, Aug 21, 2008 at 11:02 AM, Kevin Reiter <[EMAIL PROTECTED]> wrote:
>
> List Subscriptions wrote:
> : Hey Kevin,
> :
> : The reason your rule isn't working is because Snort02/Snort02 is
> : decoded as the hostname and not part of the log message (<match> is
> : used only for the log message).  Something like this would work:
> :
> : <rule id="103004" level="0">
> :    <if_sid>5104</if_sid>
> :    <hostname>Snort02/Snort02</hostname>
> :    <description>Interface (xl0) entered promiscuous mode on
> : Snort02</description>
> :  </rule>
> :
> : Upgrading to the latest snapshot will get you the amazing
> : ossec-logtest which is perfect for these situations.
>
>
> Where is it?  I just downloaded/installed the snapshot from yesterday 
> (ossec-hids-080820.tar.gz) and it isn't there.  Any idea which snapshot it's 
> contained in?  I REALLY want to play with that :)
>
>
> : 2008/08/20 11:48:13 ossec-testrule: INFO: Started (pid: 21847).
> : ossec-testrule: Type one log per line.
> :
> : Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode enabled
> :
> :
> : **Phase 1: Completed pre-decoding.
> :        full event: 'Aug 20 09:39:49 Snort02/Snort02 kernel: xl0:
> : promiscuous mode enabled'
> :        hostname: 'Snort02/Snort02'
> :        program_name: 'kernel'
> :        log: 'xl0: promiscuous mode enabled'
> :
> : **Phase 2: Completed decoding.
> :        decoder: 'iptables'
> :
> : **Phase 3: Completed filtering (rules).
> :        Rule id: '103004'
> :        Level: '0'
> :        Description: 'Interface (xl0) entered promiscuous mode on
> : Snort02'
> :
> :
> : Cheers,
> :
> : cnk
> :
> :
> :
> : On Wed, Aug 20, 2008 at 9:57 AM, Kevin Reiter <[EMAIL PROTECTED]>
> : wrote:
> ::
> :: Hello list,
> ::
> :: I'm trying to stop sending an e-mail alert when a rule fires and
> :: certain criteria are matched, as per
> :: 
> http://www.ossec.net/wiki/index.php/Know_How:Ignore_Rules#Ignoring_syslog_message
> ::
> :: Here's the alert I'm currently receiving:
> ::
> :: Received From: Snort02/Snort02->/path/to/snort.log
> :: Rule: 5104 fired (level 8) -> "Interface entered in
> :: promiscuous(sniffing) mode."
> :: Portion of the log(s):
> ::
> :: Aug 20 09:39:49 Snort02/Snort02 kernel: xl0: promiscuous mode enabled
> ::
> :: I'm restarting Snort every hour, which means I'm getting the above
> :: e-mail alert every hour.  I've added the following rule to
> :: local_rules.xml:
> ::
> :: <!-- Ignore Snort02 going into promisc mode -->
> ::
> ::  <rule id="103004" level="0">
> ::    <if_sid>5104</if_sid>
> ::    <match>Snort02</match>
> ::    <description>Interface (xl0) entered promiscuous mode on
> :: Snort02</description>  </rule>
> ::
> :: I then restarted the OSSEC server, gave it a minute, then restarted
> :: Snort, and I still get the e-mail alert.
> ::
> :: Is there something wrong with my syntax?  I'm running 1.4 (yes, I
> :: know, I need to upgrade :)
> ::
> ::
> :: Thanks,
> :: Kevin
> ::
> :: This message may contain confidential or proprietary information and
> :: is intended solely for the individual(s) to whom it is addressed.
> :: If you are not a named addressee you should not disseminate,
> :: distribute or copy this e-mail or act upon the information contained
> :: herein.  Please notify the sender immediately by e-mail if you have
> :: received this e-mail by mistake and delete this e-mail from your
> :: system.
>
>

Reply via email to