Hello
I have following in my ossec.conf file on Windows server :
<localfile>
<location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location>
<log_format>syslog</log_format>
</localfile>
Messages are coming as enabled in full log (command : logs/archives# tail -f
archives.log | grep dhcp) and look like :
2014 Dec 09 13:49:45 (PDC)
192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log
30,12/09/14,13:48:57,DNS Update
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
PDC is server name, 192.168.100.1 is server IP.
But above message is not recognized by decoder and is not handled by
ms_dhcp_rules.xml.
ossec-testrule: Type one log per line.
2014 Dec 09 13:49:45 (PDC)
192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log
30,12/09/14,13:48:57,DNS Update
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
**Phase 1: Completed pre-decoding.
full event: '2014 Dec 09 13:49:45 (PDC)
192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log
30,12/09/14,13:48:57,DNS Update
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
hostname: 'ossec'
program_name: '(null)'
log: '2014 Dec 09 13:49:45 (PDC)
192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log
30,12/09/14,13:48:57,DNS Update
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
**Phase 2: Completed decoding.
No decoder matched
How I can fix that so OSSEC will recognize above message for DHCP ?
Many thanks for an advise.
With best regards
Martynas
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.