On Mon, Dec 8, 2014 at 7:14 PM, Jarrod Farncomb <[email protected]> wrote: > I'm having an issue getting failed logins to Windows servers to log > correctly to alerts.log. > > I've created a log in fail and confirmed the Windows event logs show this as > ID 4625. > > Checking in the rules directory on the OSSEC server this appears within the > <id> field of the msauth rule file (ID 18106), however it doesn't actually > seem to detect or log it to alerts.log. > > What needs to be changed? When I run ossec-logtest and put the ID 4625 in it > says that no rules have been applied, despite there already being one that > appears to match it. >
What version of OSSEC, and can you provide a log sample? > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
