"When I run ossec-logtest and put the ID 4625 " Do you paste the entire log into the logtest?
Can you put your logtest output here? On Monday, December 8, 2014 7:14:15 PM UTC-5, Jarrod Farncomb wrote: > > I'm having an issue getting failed logins to Windows servers to log > correctly to alerts.log. > > I've created a log in fail and confirmed the Windows event logs show this > as ID 4625. > > Checking in the rules directory on the OSSEC server this appears within > the <id> field of the msauth rule file (ID 18106), however it doesn't > actually seem to detect or log it to alerts.log. > > What needs to be changed? When I run ossec-logtest and put the ID 4625 in > it says that no rules have been applied, despite there already being one > that appears to match it. > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
