Testing the OP's logs, I get an expected response.  It should be noted that 
the log message needs to be truncated from archives.log prior to passing it 
to ossec-logtest.  Even with the additional available fields in Windows 
2012, the OSSEC decoder does recognize it as an MS DHCP log file.


**Phase 1: Completed pre-decoding.
       full event: '30,12/09/14,13:48:57,DNS Update 
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0 '
       hostname: 'ossec'
       program_name: '(null)'
       log: '30,12/09/14,13:48:57,DNS Update 
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0 '
**Phase 2: Completed decoding.
       decoder: 'ms-dhcp-ipv4'
**Phase 3: Completed filtering (rules).
       Rule id: '6300'
       Level: '0'
       Description: 'Grouping for the MS-DHCP rules.'


On Wednesday, December 10, 2014 4:35:45 AM UTC-8, dan (ddpbsd) wrote:

> On Wed, Dec 10, 2014 at 5:06 AM, Martynas Buožis <[email protected] 
> <javascript:>> wrote: 
> > Hello 
> > 
> > But I am using OSSEC agent that downloaded from OSSEC. And configured it 
> to send dhcp logs, so my assumption was that this shall somehow stick 
> together on OSSEC server ? Or maybe there is a mistake in configuration for 
> DHCP logs and different format shall be selected ? 
> > 
>
> Logs stored to archives.log have a header added to them. This header 
> is not present when the log message is decoded. The fact that the log 
> message has made it to the archives.log means that the manager is 
> receiving the log message. If you run the provided log message 
> (everything from "30," to the end), it should decode properly. Give it 
> a shot. 
> If it turns out like it did for me when I did this, it'll trigger a 
> rule. The rule is level 0 though, so no real alert. You'd have to add 
> an alert for this. 
>
> > Now I have in ossec.conf for agent : 
> > 
> > <localfile> 
> >   <location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location> 
> > <log_format>syslog</log_format> </localfile> 
> > 
> > If I do not want change decoder.xml and have permeant solution not 
> affected by updates - what could be a proposal ? Copy chapter for ms-dhcp 
> from decoder.xml to local_decoder.xml, rename it in some way and add right 
> prematch ?  Current is : 
> > 
>
> I don't know what problem you are trying to solve here, so I cannot 
> provide any help. 
>
> > <decoder name="ms-dhcp-ipv4"> 
> >   <prematch>^\d\d,\d+/\d+/\d\d\d\d,\d+:\d+:\d+,|</prematch> 
> >   <prematch>^\d\d,\d+/\d+/\d\d,\d+:\d+:\d+,</prematch> 
> >   
> <regex>^(\d\d),\d+/\d+/\d\d\d*,\d+:\d+:\d+,(\.+),(\d+.\d+.\d+.\d+)</regex> 
> >   <order>id,extra_data,srcip</order> 
> > </decoder> 
> > 
> > Many thanks, 
> > Martynas 
> > 
> > 
> > -----Original Message----- 
> > From: [email protected] <javascript:> [mailto:
> [email protected] <javascript:>] On Behalf Of dan (ddp) 
> > Sent: Tuesday, December 9, 2014 5:49 PM 
> > To: [email protected] <javascript:> 
> > Subject: Re: [ossec-list] MS Windows server DHCP logs 
> > 
> > On Tue, Dec 9, 2014 at 10:19 AM, Martynas Buožis <[email protected] 
> <javascript:>> wrote: 
> >> Hello 
> >> 
> >> Yes, message is from archives.log as it was sent by ossec-agent from 
> server. But I never got it parsed into alerts.log. 
> >> 
> >> If I will change decoder.xml - will it be overwritten with a next 
> update ? 
> > 
> > Yes. 
> > 
> >> 
> >> I was expecting that  standard logs as sent by OSSEC agent should be 
> handled by default OSSEC server definitions .... 
> >> 
> > 
> > According to my tests it is. It is decoded by ms-dhcp-ipv4, and triggers 
> rule 6300 (Grouping for the MS-DHCP rules). 
> > Try running the log message through ossec-logtest without the header 
> that OSSEC adds. 
> > 
> >> Many thanks for an advice, 
> >> Martynas 
> >> 
> >> 
> >>> On 09 Dec 2014, at 14:53, dan (ddp) <[email protected] <javascript:>> 
> wrote: 
> >>> 
> >>>> On Tue, Dec 9, 2014 at 7:44 AM, dan (ddp) <[email protected] 
> <javascript:>> wrote: 
> >>>>> On Tue, Dec 9, 2014 at 6:59 AM, Martynas Buožis <[email protected] 
> <javascript:>> wrote: 
> >>>>> Hello 
> >>>>> 
> >>>>> I have following in my ossec.conf file on Windows server : 
> >>>>> 
> >>>>> <localfile> 
> >>>>>     
>  <location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location> 
> >>>>>      <log_format>syslog</log_format> </localfile> 
> >>>>> 
> >>>>> Messages are coming as enabled in full log (command : logs/archives# 
> tail -f archives.log | grep dhcp) and look like : 
> >>>>> 
> >>>>> 2014 Dec 09 13:49:45 (PDC) 
> >>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
> >>>>> 30,12/09/14,13:48:57,DNS Update 
> >>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0 
> >>>>> 
> >>>>> PDC is server name, 192.168.100.1 is server IP. 
> >>>>> 
> >>>>> But above message is not recognized by decoder and is not handled by 
> ms_dhcp_rules.xml. 
> >>>>> 
> >>>>> ossec-testrule: Type one log per line. 
> >>>>> 
> >>>>> 2014 Dec 09 13:49:45 (PDC) 
> >>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
> >>>>> 30,12/09/14,13:48:57,DNS Update 
> >>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0 
> >>>>> 
> >>>>> 
> >>>>> **Phase 1: Completed pre-decoding. 
> >>>>>       full event: '2014 Dec 09 13:49:45 (PDC) 
> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
> 30,12/09/14,13:48:57,DNS Update 
> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0' 
> >>>>>       hostname: 'ossec' 
> >>>>>       program_name: '(null)' 
> >>>>>       log: '2014 Dec 09 13:49:45 (PDC) 
> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
> 30,12/09/14,13:48:57,DNS Update 
> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0' 
> >>>>> 
> >>>>> **Phase 2: Completed decoding. 
> >>>>>       No decoder matched 
> >>>>> 
> >>>>> 
> >>>>> How I can fix that so OSSEC will recognize above message for DHCP ? 
> >>>> 
> >>>> What version of Windows is this? The logs don't look anything like 
> >>>> the samples we have for 2008 (2003?). 
> >>> 
> >>> Ooooh, I think I see an issue. Did the log sample you provided come 
> >>> from archives.log? If so, it has a header on it "2014 Dec 09 13:49:45 
> >>> (PDC) 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log ." 
> >>> Remove this header and you have a proper log message. 
> >>> 
> >>> If that log message didn't come from archives.log, find out why it's 
> >>> adding that header onto the message, or modify the decoder.xml to 
> >>> handle it (it's a 5 minute change). 
> >>> 
> >>>>> Many thanks for an advise. 
> >>>>> 
> >>>>> 
> >>>>> With best regards 
> >>>>> Martynas 
> >>>>> 
> >>>>> -- 
> >>>>> 
> >>>>> --- 
> >>>>> You received this message because you are subscribed to the Google 
> Groups "ossec-list" group. 
> >>>>> To unsubscribe from this group and stop receiving emails from it, 
> send an email to [email protected] <javascript:>. 
> >>>>> For more options, visit https://groups.google.com/d/optout. 
> >>> 
> >>> -- 
> >>> 
> >>> --- 
> >>> You received this message because you are subscribed to the Google 
> Groups "ossec-list" group. 
> >>> To unsubscribe from this group and stop receiving emails from it, send 
> an email to [email protected] <javascript:>. 
> >>> For more options, visit https://groups.google.com/d/optout. 
> >> 
> >> -- 
> >> 
> >> --- 
> >> You received this message because you are subscribed to the Google 
> Groups "ossec-list" group. 
> >> To unsubscribe from this group and stop receiving emails from it, send 
> an email to [email protected] <javascript:>. 
> >> For more options, visit https://groups.google.com/d/optout. 
> > 
> > -- 
> > 
> > --- 
> > You received this message because you are subscribed to the Google 
> Groups "ossec-list" group. 
> > To unsubscribe from this group and stop receiving emails from it, send 
> an email to [email protected] <javascript:>. 
> > For more options, visit https://groups.google.com/d/optout. 
> > 
> > -- 
> > 
> > --- 
> > You received this message because you are subscribed to the Google 
> Groups "ossec-list" group. 
> > To unsubscribe from this group and stop receiving emails from it, send 
> an email to [email protected] <javascript:>. 
> > For more options, visit https://groups.google.com/d/optout. 
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to