"When I run ossec-logtest and put the ID 4625 "

Do you paste the entire log into the logtest?

Can you put your logtest output here?



On Monday, December 8, 2014 7:14:15 PM UTC-5, Jarrod Farncomb wrote:
>
> I'm having an issue getting failed logins to Windows servers to log 
> correctly to alerts.log.
>
> I've created a log in fail and confirmed the Windows event logs show this 
> as ID 4625.
>
> Checking in the rules directory on the OSSEC server this appears within 
> the <id> field of the msauth rule file (ID 18106), however it doesn't 
> actually seem to detect or log it to alerts.log.
>
> What needs to be changed? When I run ossec-logtest and put the ID 4625 in 
> it says that no rules have been applied, despite there already being one 
> that appears to match it.
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to