I'm having an issue getting failed logins to Windows servers to log correctly to alerts.log.
I've created a log in fail and confirmed the Windows event logs show this as ID 4625. Checking in the rules directory on the OSSEC server this appears within the <id> field of the msauth rule file (ID 18106), however it doesn't actually seem to detect or log it to alerts.log. What needs to be changed? When I run ossec-logtest and put the ID 4625 in it says that no rules have been applied, despite there already being one that appears to match it. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
