Nik, Please start your own thread. Thank you, dan
On Mon, Feb 14, 2011 at 9:06 AM, Nikolaos Pavlidis <[email protected]> wrote: > Hello all, > > I am quite new to ossec so bare with me. I am trying to add some rules to > ossec so it will decode auditd syscalls. > > What I have done so far.. > > My local_decoder.xml: > > <decoder name="auditd"> > > <prematch>type=\S+ msg=audit(\S+): arch=\S+ syscall=\S+ success=\S+ > exit=\S+ a0=\S+ a1=\S+ a2=\S+ a3=\S+ items=\S+ ppid=\S+ pid=\S+ auid=\S+ > uid=\S+ gid=\S+ euid=\S+ suid=\S+ fsuid=\S+ egid=\S+ sgid=\S+ fsgid=\S+ > tty=\S+ ses=\S+</prematch> > > </decoder> > > <decoder name="auditd-modprobe"> > > <parent>auditd</parent> > > <regex offset="after_parent">^comm="(\S+)"</regex> > > <order>id</order> > > </decoder> > > my rule file: > > <rule id="91005" level="12"> > > <decoded_as>auditd-modprobe</decoded_as> > > <id>^rmmod</id> > > <description>Auditd rule to notify when a kernel module has been > removed.</description> > > </rule> > > and the log-test output: > > [root@pythia ossec]# /var/ossec/bin/ossec-logtest > > 2011/02/14 14:01:50 ossec-testrule: INFO: Reading local decoder file. > > 2011/02/14 14:01:50 ossec-testrule: INFO: Started (pid: 12076). > > ossec-testrule: Type one log per line. > > type=SYSCALL msg=audit(1297689723.890:655): arch=c000003e syscall=176 > success=yes exit=0 a0=7fff79b3e330 a1=880 a2=401990 a3=ffffffffffffffff > items=0 ppid=15035 pid=15629 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 > egid=0 sgid=0 fsgid=0 tty=pts1 ses=565 comm="rmmod" exe="/sbin/rmmod" > key="modules" > > **Phase 1: Completed pre-decoding. > > full event: 'type=SYSCALL msg=audit(1297689723.890:655): > arch=c000003e syscall=176 success=yes exit=0 a0=7fff79b3e330 a1=880 > a2=401990 a3=ffffffffffffffff items=0 ppid=15035 pid=15629 auid=1000 uid=0 > gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=565 > comm="rmmod" exe="/sbin/rmmod" key="modules"' > > hostname: 'pythia' > > program_name: '(null)' > > log: 'type=SYSCALL msg=audit(1297689723.890:655): arch=c000003e > syscall=176 success=yes exit=0 a0=7fff79b3e330 a1=880 a2=401990 > a3=ffffffffffffffff items=0 ppid=15035 pid=15629 auid=1000 uid=0 gid=0 > euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=565 comm="rmmod" > exe="/sbin/rmmod" key="modules"' > > **Phase 2: Completed decoding. > > decoder: 'auditd' > > id: 'rmmod' > > **Phase 3: Completed filtering (rules). > > Rule id: '1' > > Level: '0' > > Description: 'List of rules to be ignored.' > > I know I must be missing something here.. it should be detecting it but.... > > Any help would be much appreciated. > > Kind regards, > > Nik >
