I was just curious if anyone knew the status of the issue where IIS logs are
not able to trigger on web_rules.xml?

Basically even with a correct IIS decoder in place the web rules will never
trigger.

 

I came across some pretty obvious SQL Injection Attacks against IIS websites
and was trying to determine why OSSEC didn't catch those events.

 

So really there is no point to running IIS logs through OSSEC if you can't
trigger against rules.

 

I see the issue was raised here
https://github.com/ossec/ossec-hids/issues/164 

With possible fix here https://github.com/ossec/ossec-hids/pull/434

 

James Whittington

 

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to