Hello all,

 

I'm still enjoying OSSEC quite a bit.  This morning I discovered the
ability to use ! (bang) in front of patterns in ossecwui to exclude
events that match a pattern I specify.  This is incredibly useful when
you're in situations where there's been an explosion of thousands of
events because of a service run amok and you still want to wade through
and find anything else that may be important.  But, that's not why I'm
emailing.

 

In the web UI, I noticed that sometimes I have two events that get
smashed together into a single alert.  I'm not speaking of a composite
rule that is designed to do such a thing like "Multiple Windows Audit
Failures".  In one specific case, it's for rule 551 as shown below in a
copy-and-paste directly out of my web browser.  As you can see, an
Application event log error got concatenated onto this syscheck event
for a completely different system for no apparent reason.  In this
search that I did in the web UI, the Application error event that you
see here shouldn't have been returned at all - much less attached to
this syscheck event.  

 

Does anyone know why this happens and how I can stop it? 

 

--Begin example

 

2009 Apr 23 00:08:01 Rule Id: 551
<http://www.ossec.net/wiki/index.php/Rule:551>  level: 7
Location: (xxxxxxx.xxxxx.com) xxx.xxx.xxx.xxx->syscheck 
Integrity checksum changed again (2nd time). 

Integrity checksum changed for: 'C:\Windows/system32/jsproxy.dll'
Old md5sum was: 'e5760806966c396a1c12b39e9007aa38'
New md5sum is : '383e49164fc41adbc7cf26212ad37dd7'
Old sha1sum was: 'c2075d544405aab062cdcba442bf005b5ee40cc7'
New sha1sum is : '1f239ff0fa7a97ff21d5c9a3f3f8ef156e2c89fc'

WinEvtLog: Application: ERROR(4300): SQLsafe Management Service: (no
user): no domain: xxxxx.xxxx.com: SQLsafe Management Service version
4.9.605.3451: Could not retrieve grooming settings from repository.
Another attempt will be made in 60 seconds.

 

--End example

 

Chris Kolb
Manager of Information Security

GDSX, Ltd. 
Phone: 972-612-7121
Fax: 972-612-7021

 


Confidentiality Notice:  This e-mail contains information that is
confidential.  It is intended for the exclusive use of the individual or
entity to whom it is addressed.  If you are not the named recipient,
disclosure or distribution of the information transmitted herewith is
strictly prohibited and may be subject to legal restriction or sanction.
Please notify the sender, by return e-mail or telephone, of any
unintended recipients and delete the original message without making any
copies.

 

Reply via email to