Brent, Dan

Many thanks for your support. I got a good tip that I did not notice rule level 
0 and that was reason why I missed it in alerts file. So I created definitions 
in local_rules.xml with alert level 3 and now I see all messages as expected.

Many thanks for your assistance.

With best regards
Martynas


From: [email protected] [mailto:[email protected]] On 
Behalf Of Brent Morris
Sent: Wednesday, December 10, 2014 8:50 PM
To: [email protected]
Subject: Re: [ossec-list] MS Windows server DHCP logs

Testing the OP's logs, I get an expected response.  It should be noted that the 
log message needs to be truncated from archives.log prior to passing it to 
ossec-logtest.  Even with the additional available fields in Windows 2012, the 
OSSEC decoder does recognize it as an MS DHCP log file.


**Phase 1: Completed pre-decoding.
       full event: '30,12/09/14,13:48:57,DNS Update 
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0 '
       hostname: 'ossec'
       program_name: '(null)'
       log: '30,12/09/14,13:48:57,DNS Update 
Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0 '
**Phase 2: Completed decoding.
       decoder: 'ms-dhcp-ipv4'
**Phase 3: Completed filtering (rules).
       Rule id: '6300'
       Level: '0'
       Description: 'Grouping for the MS-DHCP rules.'


On Wednesday, December 10, 2014 4:35:45 AM UTC-8, dan (ddpbsd) wrote:
On Wed, Dec 10, 2014 at 5:06 AM, Martynas Buožis <[email protected]<javascript:>> 
wrote:
> Hello
>
> But I am using OSSEC agent that downloaded from OSSEC. And configured it to 
> send dhcp logs, so my assumption was that this shall somehow stick together 
> on OSSEC server ? Or maybe there is a mistake in configuration for DHCP logs 
> and different format shall be selected ?
>

Logs stored to archives.log have a header added to them. This header
is not present when the log message is decoded. The fact that the log
message has made it to the archives.log means that the manager is
receiving the log message. If you run the provided log message
(everything from "30," to the end), it should decode properly. Give it
a shot.
If it turns out like it did for me when I did this, it'll trigger a
rule. The rule is level 0 though, so no real alert. You'd have to add
an alert for this.

> Now I have in ossec.conf for agent :
>
> <localfile>
>   <location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location>
> <log_format>syslog</log_format> </localfile>
>
> If I do not want change decoder.xml and have permeant solution not affected 
> by updates - what could be a proposal ? Copy chapter for ms-dhcp from 
> decoder.xml to local_decoder.xml, rename it in some way and add right 
> prematch ?  Current is :
>

I don't know what problem you are trying to solve here, so I cannot
provide any help.

> <decoder name="ms-dhcp-ipv4">
>   <prematch>^\d\d,\d+/\d+/\d\d\d\d,\d+:\d+:\d+,|</prematch>
>   <prematch>^\d\d,\d+/\d+/\d\d,\d+:\d+:\d+,</prematch>
>   <regex>^(\d\d),\d+/\d+/\d\d\d*,\d+:\d+:\d+,(\.+),(\d+.\d+.\d+.\d+)</regex>
>   <order>id,extra_data,srcip</order>
> </decoder>
>
> Many thanks,
> Martynas
>
>
> -----Original Message-----
> From: [email protected]<javascript:> 
> [mailto:[email protected]<javascript:>] On Behalf Of dan (ddp)
> Sent: Tuesday, December 9, 2014 5:49 PM
> To: [email protected]<javascript:>
> Subject: Re: [ossec-list] MS Windows server DHCP logs
>
> On Tue, Dec 9, 2014 at 10:19 AM, Martynas Buožis <[email protected]<javascript:>> 
> wrote:
>> Hello
>>
>> Yes, message is from archives.log as it was sent by ossec-agent from server. 
>> But I never got it parsed into alerts.log.
>>
>> If I will change decoder.xml - will it be overwritten with a next update ?
>
> Yes.
>
>>
>> I was expecting that  standard logs as sent by OSSEC agent should be handled 
>> by default OSSEC server definitions ....
>>
>
> According to my tests it is. It is decoded by ms-dhcp-ipv4, and triggers rule 
> 6300 (Grouping for the MS-DHCP rules).
> Try running the log message through ossec-logtest without the header that 
> OSSEC adds.
>
>> Many thanks for an advice,
>> Martynas
>>
>>
>>> On 09 Dec 2014, at 14:53, dan (ddp) <[email protected]<javascript:>> wrote:
>>>
>>>> On Tue, Dec 9, 2014 at 7:44 AM, dan (ddp) <[email protected]<javascript:>> 
>>>> wrote:
>>>>> On Tue, Dec 9, 2014 at 6:59 AM, Martynas Buožis 
>>>>> <[email protected]<javascript:>> wrote:
>>>>> Hello
>>>>>
>>>>> I have following in my ossec.conf file on Windows server :
>>>>>
>>>>> <localfile>
>>>>>      <location>C:\Windows\sysnative\dhcp\DhcpSrvLog-%a.log</location>
>>>>>      <log_format>syslog</log_format> </localfile>
>>>>>
>>>>> Messages are coming as enabled in full log (command : logs/archives# tail 
>>>>> -f archives.log | grep dhcp) and look like :
>>>>>
>>>>> 2014 Dec 09 13:49:45 (PDC)
>>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log
>>>>> 30,12/09/14,13:48:57,DNS Update
>>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
>>>>>
>>>>> PDC is server name, 192.168.100.1 is server IP.
>>>>>
>>>>> But above message is not recognized by decoder and is not handled by 
>>>>> ms_dhcp_rules.xml.
>>>>>
>>>>> ossec-testrule: Type one log per line.
>>>>>
>>>>> 2014 Dec 09 13:49:45 (PDC)
>>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log
>>>>> 30,12/09/14,13:48:57,DNS Update
>>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0
>>>>>
>>>>>
>>>>> **Phase 1: Completed pre-decoding.
>>>>>       full event: '2014 Dec 09 13:49:45 (PDC) 
>>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>>>> 30,12/09/14,13:48:57,DNS Update 
>>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
>>>>>       hostname: 'ossec'
>>>>>       program_name: '(null)'
>>>>>       log: '2014 Dec 09 13:49:45 (PDC) 
>>>>> 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log 
>>>>> 30,12/09/14,13:48:57,DNS Update 
>>>>> Request,192.168.101.71,host.domain.local,,,0,6,,,,,,,,,0'
>>>>>
>>>>> **Phase 2: Completed decoding.
>>>>>       No decoder matched
>>>>>
>>>>>
>>>>> How I can fix that so OSSEC will recognize above message for DHCP ?
>>>>
>>>> What version of Windows is this? The logs don't look anything like
>>>> the samples we have for 2008 (2003?).
>>>
>>> Ooooh, I think I see an issue. Did the log sample you provided come
>>> from archives.log? If so, it has a header on it "2014 Dec 09 13:49:45
>>> (PDC) 192.168.100.1->\Windows\sysnative\dhcp\DhcpSrvLog-Tue.log ."
>>> Remove this header and you have a proper log message.
>>>
>>> If that log message didn't come from archives.log, find out why it's
>>> adding that header onto the message, or modify the decoder.xml to
>>> handle it (it's a 5 minute change).
>>>
>>>>> Many thanks for an advise.
>>>>>
>>>>>
>>>>> With best regards
>>>>> Martynas
>>>>>
>>>>> --
>>>>>
>>>>> ---
>>>>> You received this message because you are subscribed to the Google Groups 
>>>>> "ossec-list" group.
>>>>> To unsubscribe from this group and stop receiving emails from it, send an 
>>>>> email to [email protected]<javascript:>.
>>>>> For more options, visit https://groups.google.com/d/optout.
>>>
>>> --
>>>
>>> ---
>>> You received this message because you are subscribed to the Google Groups 
>>> "ossec-list" group.
>>> To unsubscribe from this group and stop receiving emails from it, send an 
>>> email to [email protected]<javascript:>.
>>> For more options, visit https://groups.google.com/d/optout.
>>
>> --
>>
>> ---
>> You received this message because you are subscribed to the Google Groups 
>> "ossec-list" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email to [email protected]<javascript:>.
>> For more options, visit https://groups.google.com/d/optout.
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups 
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected]<javascript:>.
> For more options, visit https://groups.google.com/d/optout.
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups 
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected]<javascript:>.
> For more options, visit https://groups.google.com/d/optout.
--

---
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to 
[email protected]<mailto:[email protected]>.
For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to