On Mon, Dec 8, 2014 at 7:14 PM, Jarrod Farncomb <[email protected]> wrote:
> I'm having an issue getting failed logins to Windows servers to log
> correctly to alerts.log.
>
> I've created a log in fail and confirmed the Windows event logs show this as
> ID 4625.
>
> Checking in the rules directory on the OSSEC server this appears within the
> <id> field of the msauth rule file (ID 18106), however it doesn't actually
> seem to detect or log it to alerts.log.
>
> What needs to be changed? When I run ossec-logtest and put the ID 4625 in it
> says that no rules have been applied, despite there already being one that
> appears to match it.
>

What version of OSSEC, and can you provide a log sample?

> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to