Guys,

I have a domain controller with ossec agent. Below default rules of ossec:

  <rule id="18139" level="5">
    <if_sid>18105</if_sid>
    <id>^672|^673|^675|^676|^681|^4769</id>
    <description>Windows DC Logon Failure.</description>
    <group>win_authentication_failed,</group>
  </rule>

Logon failed put the information in my log files:

Rule: 18139 (level 5) -> 'Windows DC Logon Failure.'
Src IP: (none)
User: SYSTEM
WinEvtLog: Security: AUDIT_FAILURE(675): Security: SYSTEM: NT AUTHORITY: Server1: Pre-authentication failed: User Name: user1 User ID: %{S-1-5-21-741071929 -3511550341-2332304184-4593} Service Name: krbtgt/INTRANET.COM.BR Pre-Authentication Type: 0x0 Failure Code: 0x19 Client Address: 192.168.1.7
0

Take a look in Src IP section (none), because that the active response don't works for this event.

What should I do?

--
Atenciosamente,

Rafael Brito Gomes
Analista de Segurança
LPIC-1 MCSO
DISUP/CPD/UFBA
Tel : +55 71 3283 6100

Reply via email to