I have install Ossec 1.6 and am not able to get the decoder to work
for Aruba logs using the ossec-logtest.

Thanks

This is the local rule I'm using:
   <rule id="100051" level="15">
    <match>is associating to a Rogue AP with SSID</match>
    <if_fts />
    <description>Client Associating with Rogue AP Detected</
description>
  </rule>

Log entry used:
Sep  8 16:44:53 aruba-controller.company.com [192.168.0.24] sapd[157]:
<106008> <ERRS> |AP [EMAIL PROTECTED] sapd|  AM 00:0b:86:e1:df:00:
STA with MAC 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID
Linksys Router and BSSID 00:18:39:cc:63:9f

Ossec-logtest output:
Sep  8 16:44:53 aruba-controller.company.com [192.168.0.24] sapd[157]:
<106008> <ERRS> |AP [EMAIL PROTECTED] sapd|  AM 00:0b:86:e1:df:00:
STA with MAC 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID
Linksys Router and BSSID 00:18:39:cc:63:9f


**Phase 1: Completed pre-decoding.
       full event: 'Sep  8 16:44:53 aruba-controller.company.com
[192.168.0.24] sapd[157]: <106008> <ERRS> |AP [EMAIL PROTECTED]
sapd|  AM 00:0b:86:e1:df:00: STA with MAC 00:17:f2:47:5f:0f is
associating to a Rogue AP with SSID Linksys Router and BSSID
00:18:39:cc:63:9f'
       hostname: 'aruba-controller.company.com'
       program_name: ''
       log: ''

**Phase 2: Completed decoding.
       No decoder matched.

Reply via email to