Guys,
I have a domain controller with ossec agent. Below default rules of ossec:
<rule id="18139" level="5">
<if_sid>18105</if_sid>
<id>^672|^673|^675|^676|^681|^4769</id>
<description>Windows DC Logon Failure.</description>
<group>win_authentication_failed,</group>
</rule>
Logon failed put the information in my log files:
Rule: 18139 (level 5) -> 'Windows DC Logon Failure.'
Src IP: (none)
User: SYSTEM
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY:
Server1: Pre-authentication failed: User Name: user1 User
ID: %{S-1-5-21-741071929
-3511550341-2332304184-4593} Service Name:
krbtgt/INTRANET.COM.BR Pre-Authentication Type: 0x0
Failure Code: 0x19 Client Address: 192.168.1.7
0
Take a look in Src IP section (none), because that the active response
don't works for this event.
What should I do?
--
Atenciosamente,
Rafael Brito Gomes
Analista de Segurança
LPIC-1 MCSO
DISUP/CPD/UFBA
Tel : +55 71 3283 6100