Interesting...

I hadn't realized my IIS log files were being completely ignored.

If I put my IIS server in IIS or NCSA logging mode... They are decoded as 
PureFTPD logs using ossec-logtest

In W3C format - they come out like this..

**Phase 3: Completed filtering (rules).
       Rule id: '31100'
       Level: '0'
       Description: 'Access log messages grouped.

sample used..

2014-12-12 18:23:44 W3SVC1 SERVER-NAME 1.2.3.4 GET 
/Scripts/..%5c..%5cwinnt/system32/cmd.exe /c+dir+\ 443 - 1.2.3.4 
Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko 404 11 
0 0

Then some of the longer ActiveSync logs are just lost on the decoder... 
with 

**Phase 2: Completed decoding.
       No decoder matched.

It would be great to resolve this issue.  IIS keeps me up at night since 
it's probably our biggest liability.  Let me know how I can help.  I can 
provide logs (would prefer not to post them here though).

On Friday, December 12, 2014 7:37:15 AM UTC-8, James Whittington wrote:

> I was just curious if anyone knew the status of the issue where IIS logs 
> are not able to trigger on web_rules.xml?
>
> Basically even with a correct IIS decoder in place the web rules will 
> never trigger.
>
>  
>
> I came across some pretty obvious SQL Injection Attacks against IIS 
> websites and was trying to determine why OSSEC didn’t catch those events.
>
>  
>
> So really there is no point to running IIS logs through OSSEC if you can’t 
> trigger against rules.
>
>  
>
> I see the issue was raised here 
> https://github.com/ossec/ossec-hids/issues/164 
>
> With possible fix here https://github.com/ossec/ossec-hids/pull/434
>
>  
>
> James Whittington
>
>  
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to