I'm having an issue getting failed logins to Windows servers to log 
correctly to alerts.log.

I've created a log in fail and confirmed the Windows event logs show this 
as ID 4625.

Checking in the rules directory on the OSSEC server this appears within the 
<id> field of the msauth rule file (ID 18106), however it doesn't actually 
seem to detect or log it to alerts.log.

What needs to be changed? When I run ossec-logtest and put the ID 4625 in 
it says that no rules have been applied, despite there already being one 
that appears to match it.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to