Hello 

Yes, message is from archives.log as it was sent by ossec-agent from server. 
But I never got it parsed into alerts.log.

If I will change decoder.xml - will it be overwritten with a next update ? 

I was expecting that  standard logs as sent by OSSEC agent should be handled by 
default OSSEC server definitions ....

Many thanks for an advice,
Martynas


> On 09 Dec 2014, at 14:53, dan (ddp) <[email protected]> wrote:
> 
>> On Tue, Dec 9, 2014 at 7:44 AM, dan (ddp) <[email protected]> wrote:
>>> On Tue, Dec 9, 2014 at 6:59 AM, Martynas Buožis <[email protected]> wrote:
>>> Hello
>>> 
>>> I have following in my ossec.conf file on Windows server :
>>> 
>>> <localfile>
>>>      <location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location>
>>>      <log_format>syslog</log_format>
>>> </localfile>
>>> 
>>> Messages are coming as enabled in full log (command : logs/archives# tail 
>>> -f archives.log | grep dhcp) and look like :
>>> 
>>> 2014 Dec 09 13:49:45 (PDC) 
>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>> 30,12/09/14,13:48:57,DNS Update 
>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
>>> 
>>> PDC is server name, 192.168.100.1 is server IP.
>>> 
>>> But above message is not recognized by decoder and is not handled by 
>>> ms_dhcp_rules.xml.
>>> 
>>> ossec-testrule: Type one log per line.
>>> 
>>> 2014 Dec 09 13:49:45 (PDC) 
>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>> 30,12/09/14,13:48:57,DNS Update 
>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
>>> 
>>> 
>>> **Phase 1: Completed pre-decoding.
>>>       full event: '2014 Dec 09 13:49:45 (PDC) 
>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>> 30,12/09/14,13:48:57,DNS Update 
>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
>>>       hostname: 'ossec'
>>>       program_name: '(null)'
>>>       log: '2014 Dec 09 13:49:45 (PDC) 
>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>> 30,12/09/14,13:48:57,DNS Update 
>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
>>> 
>>> **Phase 2: Completed decoding.
>>>       No decoder matched
>>> 
>>> 
>>> How I can fix that so OSSEC will recognize above message for DHCP ?
>> 
>> What version of Windows is this? The logs don't look anything like the
>> samples we have for 2008 (2003?).
> 
> Ooooh, I think I see an issue. Did the log sample you provided come
> from archives.log? If so, it has a header on it "2014 Dec 09 13:49:45
> (PDC) 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log ."
> Remove this header and you have a proper log message.
> 
> If that log message didn't come from archives.log, find out why it's
> adding that header onto the message, or modify the decoder.xml to
> handle it (it's a 5 minute change).
> 
>>> Many thanks for an advise.
>>> 
>>> 
>>> With best regards
>>> Martynas
>>> 
>>> --
>>> 
>>> ---
>>> You received this message because you are subscribed to the Google Groups 
>>> "ossec-list" group.
>>> To unsubscribe from this group and stop receiving emails from it, send an 
>>> email to [email protected].
>>> For more options, visit https://groups.google.com/d/optout.
> 
> -- 
> 
> --- 
> You received this message because you are subscribed to the Google Groups 
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to