OSSEC-HIDS 1.6.1
libprelude-0.9.21.3
libpreludedb-0.9.15.1
prelude-lml-0.9.14

It appears to me that OSSEC's might not be getting the 
assessment.impact.completion 
part of the IDMEF path correct.

For example, for this ipmon log of a blocked packet
        Jan 22 23:00:00 10.11.12.13 ipmon[94] 23:00:00.111111 sis4 @200:8 
b 10.20.20.20,2020 -> 10.10.10.10,111 PR tcp len 20 48 -S IN 
ossec generates an IDMEF alert with  assessment.impact.completion = 
succeeded, 
whereas all of the other prelude agents I use treat firewall fail/deny as 
a completion = failed.

Moreover, the IDMEF alerts for both of these logs
        WinEvtLog: Security: AUDIT_SUCCESS(673): Security: SYSTEM: NT 
AUTHORITY: SERVER: u...@domain DOMAIN PC$ %{SOMERANDOMUIDHERE} 0x40810010 
0x17 10.10.10.10 - {SOMEOTHERUID} - 
        WinEvtLog: Security: AUDIT_FAILURE(673): Security: SYSTEM: NT 
AUTHORITY: SERVER: - 0x2 - 10.10.10.10 0x20 - - 
have assessment.impact.completion = succeeded

In fact, it seems to set completion = succeeded on all of it's IDMEF 
alerts.

Is this a bug?  Or is prelude support/integration not quite finished?


Dean Takemori
Tech Support Supervisor
TD Food Group
[email protected]

Reply via email to