OSSEC-HIDS 1.6.1
libprelude-0.9.21.3
libpreludedb-0.9.15.1
prelude-lml-0.9.14
It appears to me that OSSEC's might not be getting the
assessment.impact.completion
part of the IDMEF path correct.
For example, for this ipmon log of a blocked packet
Jan 22 23:00:00 10.11.12.13 ipmon[94] 23:00:00.111111 sis4 @200:8
b 10.20.20.20,2020 -> 10.10.10.10,111 PR tcp len 20 48 -S IN
ossec generates an IDMEF alert with assessment.impact.completion =
succeeded,
whereas all of the other prelude agents I use treat firewall fail/deny as
a completion = failed.
Moreover, the IDMEF alerts for both of these logs
WinEvtLog: Security: AUDIT_SUCCESS(673): Security: SYSTEM: NT
AUTHORITY: SERVER: u...@domain DOMAIN PC$ %{SOMERANDOMUIDHERE} 0x40810010
0x17 10.10.10.10 - {SOMEOTHERUID} -
WinEvtLog: Security: AUDIT_FAILURE(673): Security: SYSTEM: NT
AUTHORITY: SERVER: - 0x2 - 10.10.10.10 0x20 - -
have assessment.impact.completion = succeeded
In fact, it seems to set completion = succeeded on all of it's IDMEF
alerts.
Is this a bug? Or is prelude support/integration not quite finished?
Dean Takemori
Tech Support Supervisor
TD Food Group
[email protected]