On Mon, Sep 10, 2012 at 2:34 PM, C. L. Martinez <[email protected]> wrote: > > > On Monday, September 10, 2012, dan (ddp) <[email protected]> wrote: >> On Sat, Sep 8, 2012 at 6:55 PM, carlopmart <[email protected]> wrote: >>> Hi all, >>> >>> Recently, I have setup a custom decoder to decode OpenBSD packet filter >>> logs. All works ok, except when certain packet filter logs arrives to >>> ossec >>> manager (all of them about queries to ntp servers), like this one: >>> >>> Sep 8 22:17:42 homefw obsdfw: Sep 08 22:17:41.670216 rule 29/(match) >>> [uid >>> 0, pid 6803] pass out on em1: 172.17.35.2.46932 > 176.74.25.243.123: [udp >>> sum ok] v4 client strat 0 poll 0 prec 0 dist 0.000000 disp 0.000000 ref >>> (unspec)@0.000000000 orig 0.000000000 rec -0.000000000 xmt >>> +539699832.364563345 [tos 0x10] (ttl 64, id 64826, len 76, bad cksum 38!) >>> >>> Whit this type of log, rule 1002 is triggered: >>> >>> Sep 8 22:17:42 bombadil obsdfw: Sep 08 22:17:41.670216 rule 29/(match) >>> [uid >>> 0, pid 6803] pass out on em1: 172.17.35.2.46932 > 176.74.25.243.123: [udp >>> sum ok] v4 client strat 0 poll 0 prec 0 dist 0.000000 disp 0.000000 ref >>> (unspec)@0.000000000 orig 0.000000000 rec -0.000000000 xmt >>> +539699832.364563345 [tos 0x10] (ttl 64, id 64826, len 76, bad cksum 38!) >>> >>> >>> **Phase 1: Completed pre-decoding. >>> full event: 'Sep 8 22:17:42 homefw obsdfw: Sep 08 22:17:41.670216 >>> rule 29/(match) [uid 0, pid 6803] pass out on em1: 172.17.35.2.46932 > >>> 176.74.25.243.123: [udp sum ok] v4 client strat 0 poll 0 prec 0 dist >>> 0.000000 disp 0.000000 ref (unspec)@0.000000000 orig 0.000000000 rec >>> -0.000000000 xmt +539699832.364563345 [tos 0x10] (ttl 64, id 64826, len >>> 76, >>> bad cksum 38!)' >>> hostname: 'homefw' >>> program_name: 'obsdfw' >>> log: 'Sep 08 22:17:41.670216 rule 29/(match) [uid 0, pid 6803] >>> pass >>> out on em1: 172.17.35.2.46932 > 176.74.25.243.123: [udp sum ok] v4 client >>> strat 0 poll 0 prec 0 dist 0.000000 disp 0.000000 ref >>> (unspec)@0.000000000 >>> orig 0.000000000 rec -0.000000000 xmt +539699832.364563345 [tos 0x10] >>> (ttl >>> 64, id 64826, len 76, bad cksum 38!)' >>> >>> **Phase 2: Completed decoding. >>> decoder: 'custom-openbsd-pf' >>> action: 'pass' >>> extra_data: 'em1' >>> srcip: '172.17.35.2' >>> srcport: '46932' >>> dstip: '176.74.25.243' >>> dstport: '123' >>> proto: 'udp' >>> >>> **Phase 3: Completed filtering (rules). >>> Rule id: '1002' >>> Level: '2' >>> Description: 'Unknown problem somewhere in the system.' >>> **Alert to be generated. >>> >>> As I can see, rule 1002 is triggered because "bad" word appears in this >>> log >>> ... but this is not a "Unknown problem somewhere in the system.". It is a >>> false possitive. >>> >>> Is it possible to disable rule 1002 only for this case??. For example, >>> whem >>> my cutom-openbsd-pf decoder is used, disable rule 1002 ... >>> >>> Thanks. >>> >>> -- >>> CL Martinez >>> carlopmart {at} gmail {d0t} com >> >> Why not create a rule to filter this out? >> >> <rule id="STUFF" level="0"> >> <if_sid>1002</if_sid> >> <decoded_as>custom-openbsd-pf</decoded_as> >> <match>bad cksum</match> >> <proto>udp</proto> >> <dstport>123</dstport> >> <description>Ignore this.</description> >> </rule> >> >> (This is totally untested, so I could have mistyped something or >> dstport may not be available, etc.) >> > > Thanks dan but I need to catch this "alert" as good. It can not be > discarded.
I don't understand? You need an alert that says this log message is ok? Change the description and level. If that is what you want, could you explain why you want it to alert on something "not bad?"
