Hi,

Yes, it was fixed on v1.6.1. Please give it a try and let us know how it goes..

Thanks,

--
Daniel B. Cid
dcid ( at ) ossec.net

On Wed, Oct 22, 2008 at 10:04 AM, simpsonlang <[EMAIL PROTECTED]> wrote:
>
> I never got a reply on this. Was this fixed in 1.6.1?
>
> On Sep 12, 3:38 pm, simpsonlang <[EMAIL PROTECTED]> wrote:
>> Just gave it a shot and this time the log: section shows something but
>> nothing matched the decoder.
>>
>> Sep  8 16:44:53aruba-controller.company.com [192.168.0.24] sapd[157]:
>> <106008> <ERRS> |[EMAIL PROTECTED] sapd|  AM 00:0b:86:e1:df:00:
>> STA with MAC 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID
>> Linksys Router and BSSID 00:18:39:cc:63:9f
>>
>> **Phase 1: Completed pre-decoding.
>>        full event: 'Sep  8 16:44:53aruba-controller.company.com
>> [192.168.0.24] sapd[157]: <106008> <ERRS> |[EMAIL PROTECTED]
>> sapd|  AM 00:0b:86:e1:df:00: STA with MAC 00:17:f2:47:5f:0f is
>> associating to a Rogue AP with SSID Linksys Router and BSSID
>> 00:18:39:cc:63:9f'
>>        hostname: 'aruba-controller.company.com'
>>        program_name: '(null)'
>>        log: '[192.168.0.24] sapd[157]: <106008> <ERRS> |AParuba-
>> [EMAIL PROTECTED] sapd|  AM 00:0b:86:e1:df:00: STA with MAC
>> 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID Linksys
>> Router and BSSID 00:18:39:cc:63:9f'
>>
>> **Phase 2: Completed decoding.
>>        No decoder matched.
>>
>> On Sep 12, 2:00 pm, "Daniel Cid" <[EMAIL PROTECTED]> wrote:
>>
>> > Hi,
>>
>> > Can you try with the following snapshot:
>>
>> >http://www.ossec.net/files/snapshots/ossec-hids-080912.tar.gz
>>
>> > It was a bug relating how we were parsing this specific syslog format
>> > (with the ip address
>> > following the hostname, instead of the program name).
>>
>> > Thanks,
>>
>> > --
>> > Daniel B. Cid
>> > dcid ( at ) ossec.net
>>
>> > On Mon, Sep 8, 2008 at 2:04 PM, simpsonlang <[EMAIL PROTECTED]> wrote:
>>
>> > > I have install Ossec 1.6 and am not able to get the decoder to work
>> > > forArubalogs using the ossec-logtest.
>>
>> > > Thanks
>>
>> > > This is the local rule I'm using:
>> > >   <rule id="100051" level="15">
>> > >    <match>is associating to a Rogue AP with SSID</match>
>> > >    <if_fts />
>> > >    <description>Client Associating with Rogue AP Detected</
>> > > description>
>> > >  </rule>
>>
>> > > Log entry used:
>> > > Sep  8 16:44:53aruba-controller.company.com [192.168.0.24] sapd[157]:
>> > > <106008> <ERRS> |[EMAIL PROTECTED] sapd|  AM 00:0b:86:e1:df:00:
>> > > STA with MAC 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID
>> > > Linksys Router and BSSID 00:18:39:cc:63:9f
>>
>> > > Ossec-logtest output:
>> > > Sep  8 16:44:53aruba-controller.company.com [192.168.0.24] sapd[157]:
>> > > <106008> <ERRS> |[EMAIL PROTECTED] sapd|  AM 00:0b:86:e1:df:00:
>> > > STA with MAC 00:17:f2:47:5f:0f is associating to a Rogue AP with SSID
>> > > Linksys Router and BSSID 00:18:39:cc:63:9f
>>
>> > > **Phase 1: Completed pre-decoding.
>> > >       full event: 'Sep  8 16:44:53aruba-controller.company.com
>> > > [192.168.0.24] sapd[157]: <106008> <ERRS> |[EMAIL PROTECTED]
>> > > sapd|  AM 00:0b:86:e1:df:00: STA with MAC 00:17:f2:47:5f:0f is
>> > > associating to a Rogue AP with SSID Linksys Router and BSSID
>> > > 00:18:39:cc:63:9f'
>> > >       hostname: 'aruba-controller.company.com'
>> > >       program_name: ''
>> > >       log: ''
>>
>> > > **Phase 2: Completed decoding.
>> > >       No decoder matched.
>

Reply via email to