Interesting...
I hadn't realized my IIS log files were being completely ignored.
If I put my IIS server in IIS or NCSA logging mode... They are decoded as
PureFTPD logs using ossec-logtest
In W3C format - they come out like this..
**Phase 3: Completed filtering (rules).
Rule id: '31100'
Level: '0'
Description: 'Access log messages grouped.
sample used..
2014-12-12 18:23:44 W3SVC1 SERVER-NAME 1.2.3.4 GET
/Scripts/..%5c..%5cwinnt/system32/cmd.exe /c+dir+\ 443 - 1.2.3.4
Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko 404 11
0 0
Then some of the longer ActiveSync logs are just lost on the decoder...
with
**Phase 2: Completed decoding.
No decoder matched.
It would be great to resolve this issue. IIS keeps me up at night since
it's probably our biggest liability. Let me know how I can help. I can
provide logs (would prefer not to post them here though).
On Friday, December 12, 2014 7:37:15 AM UTC-8, James Whittington wrote:
> I was just curious if anyone knew the status of the issue where IIS logs
> are not able to trigger on web_rules.xml?
>
> Basically even with a correct IIS decoder in place the web rules will
> never trigger.
>
>
>
> I came across some pretty obvious SQL Injection Attacks against IIS
> websites and was trying to determine why OSSEC didn’t catch those events.
>
>
>
> So really there is no point to running IIS logs through OSSEC if you can’t
> trigger against rules.
>
>
>
> I see the issue was raised here
> https://github.com/ossec/ossec-hids/issues/164
>
> With possible fix here https://github.com/ossec/ossec-hids/pull/434
>
>
>
> James Whittington
>
>
>
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.