Hello

But I am using OSSEC agent that downloaded from OSSEC. And configured it to 
send dhcp logs, so my assumption was that this shall somehow stick together on 
OSSEC server ? Or maybe there is a mistake in configuration for DHCP logs and 
different format shall be selected ?

Now I have in ossec.conf for agent :

<localfile>
  <location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location>
<log_format>syslog</log_format> </localfile>

If I do not want change decoder.xml and have permeant solution not affected by 
updates - what could be a proposal ? Copy chapter for ms-dhcp from decoder.xml 
to local_decoder.xml, rename it in some way and add right prematch ?  Current 
is :

<decoder name="ms-dhcp-ipv4">
  <prematch>^\d\d,\d+/\d+/\d\d\d\d,\d+:\d+:\d+,|</prematch>
  <prematch>^\d\d,\d+/\d+/\d\d,\d+:\d+:\d+,</prematch>
  <regex>^(\d\d),\d+/\d+/\d\d\d*,\d+:\d+:\d+,(\.+),(\d+.\d+.\d+.\d+)</regex>
  <order>id,extra_data,srcip</order>
</decoder>

Many thanks,
Martynas


-----Original Message-----
From: [email protected] [mailto:[email protected]] On 
Behalf Of dan (ddp)
Sent: Tuesday, December 9, 2014 5:49 PM
To: [email protected]
Subject: Re: [ossec-list] MS Windows server DHCP logs

On Tue, Dec 9, 2014 at 10:19 AM, Martynas Buožis <[email protected]> wrote:
> Hello
>
> Yes, message is from archives.log as it was sent by ossec-agent from server. 
> But I never got it parsed into alerts.log.
>
> If I will change decoder.xml - will it be overwritten with a next update ?

Yes.

>
> I was expecting that  standard logs as sent by OSSEC agent should be handled 
> by default OSSEC server definitions ....
>

According to my tests it is. It is decoded by ms-dhcp-ipv4, and triggers rule 
6300 (Grouping for the MS-DHCP rules).
Try running the log message through ossec-logtest without the header that OSSEC 
adds.

> Many thanks for an advice,
> Martynas
>
>
>> On 09 Dec 2014, at 14:53, dan (ddp) <[email protected]> wrote:
>>
>>> On Tue, Dec 9, 2014 at 7:44 AM, dan (ddp) <[email protected]> wrote:
>>>> On Tue, Dec 9, 2014 at 6:59 AM, Martynas Buožis <[email protected]> wrote:
>>>> Hello
>>>>
>>>> I have following in my ossec.conf file on Windows server :
>>>>
>>>> <localfile>
>>>>      <location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location>
>>>>      <log_format>syslog</log_format> </localfile>
>>>>
>>>> Messages are coming as enabled in full log (command : logs/archives# tail 
>>>> -f archives.log | grep dhcp) and look like :
>>>>
>>>> 2014 Dec 09 13:49:45 (PDC) 
>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>>> 30,12/09/14,13:48:57,DNS Update 
>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
>>>>
>>>> PDC is server name, 192.168.100.1 is server IP.
>>>>
>>>> But above message is not recognized by decoder and is not handled by 
>>>> ms_dhcp_rules.xml.
>>>>
>>>> ossec-testrule: Type one log per line.
>>>>
>>>> 2014 Dec 09 13:49:45 (PDC) 
>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>>> 30,12/09/14,13:48:57,DNS Update 
>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
>>>>
>>>>
>>>> **Phase 1: Completed pre-decoding.
>>>>       full event: '2014 Dec 09 13:49:45 (PDC) 
>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>>> 30,12/09/14,13:48:57,DNS Update 
>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
>>>>       hostname: 'ossec'
>>>>       program_name: '(null)'
>>>>       log: '2014 Dec 09 13:49:45 (PDC) 
>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>>> 30,12/09/14,13:48:57,DNS Update 
>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
>>>>
>>>> **Phase 2: Completed decoding.
>>>>       No decoder matched
>>>>
>>>>
>>>> How I can fix that so OSSEC will recognize above message for DHCP ?
>>>
>>> What version of Windows is this? The logs don't look anything like 
>>> the samples we have for 2008 (2003?).
>>
>> Ooooh, I think I see an issue. Did the log sample you provided come 
>> from archives.log? If so, it has a header on it "2014 Dec 09 13:49:45
>> (PDC) 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log ."
>> Remove this header and you have a proper log message.
>>
>> If that log message didn't come from archives.log, find out why it's 
>> adding that header onto the message, or modify the decoder.xml to 
>> handle it (it's a 5 minute change).
>>
>>>> Many thanks for an advise.
>>>>
>>>>
>>>> With best regards
>>>> Martynas
>>>>
>>>> --
>>>>
>>>> ---
>>>> You received this message because you are subscribed to the Google Groups 
>>>> "ossec-list" group.
>>>> To unsubscribe from this group and stop receiving emails from it, send an 
>>>> email to [email protected].
>>>> For more options, visit https://groups.google.com/d/optout.
>>
>> --
>>
>> ---
>> You received this message because you are subscribed to the Google Groups 
>> "ossec-list" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email to [email protected].
>> For more options, visit https://groups.google.com/d/optout.
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups 
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.

-- 

---
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to