I was just curious if anyone knew the status of the issue where IIS logs are not able to trigger on web_rules.xml?
Basically even with a correct IIS decoder in place the web rules will never trigger. I came across some pretty obvious SQL Injection Attacks against IIS websites and was trying to determine why OSSEC didn't catch those events. So really there is no point to running IIS logs through OSSEC if you can't trigger against rules. I see the issue was raised here https://github.com/ossec/ossec-hids/issues/164 With possible fix here https://github.com/ossec/ossec-hids/pull/434 James Whittington -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
