I have install Ossec 1.6 and am not able to get the decoder to work
for Aruba logs using the ossec-logtest.
Thanks
This is the local rule I'm using:
<rule id="100051" level="15">
<match>is associating to a Rogue AP with SSID</match>
<if_fts />
<description>Client Associating with Rogue AP Detected</
description>
</rule>
Log entry used:
Sep 8 16:44:53 aruba-controller.company.com [192.168.0.24] sapd[157]:
<106008> <ERRS> |AP [EMAIL PROTECTED] sapd| AM 00:0b:86:e1:df:00:
STA with MAC 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID
Linksys Router and BSSID 00:18:39:cc:63:9f
Ossec-logtest output:
Sep 8 16:44:53 aruba-controller.company.com [192.168.0.24] sapd[157]:
<106008> <ERRS> |AP [EMAIL PROTECTED] sapd| AM 00:0b:86:e1:df:00:
STA with MAC 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID
Linksys Router and BSSID 00:18:39:cc:63:9f
**Phase 1: Completed pre-decoding.
full event: 'Sep 8 16:44:53 aruba-controller.company.com
[192.168.0.24] sapd[157]: <106008> <ERRS> |AP [EMAIL PROTECTED]
sapd| AM 00:0b:86:e1:df:00: STA with MAC 00:17:f2:47:5f:0f is
associating to a Rogue AP with SSID Linksys Router and BSSID
00:18:39:cc:63:9f'
hostname: 'aruba-controller.company.com'
program_name: ''
log: ''
**Phase 2: Completed decoding.
No decoder matched.