OK - on another system I'm able to get the web_rules.xml to trigger.
I setup IIS logging on this system... in W3C format. selected all the
fields..
#Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem
cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie)
cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes
cs-bytes time-taken
OSSEC config on the monitored system looks like this.
<localfile>
<location>C:\inetpub\logs\LogFiles\W3SVC1\u_ex%y%m%d.log</location>
<log_format>iis</log_format>
</localfile>
restarted the ossec agent.... and iisreset too...
hammered on it for cmd.exe
and zoop zoop!
OSSEC HIDS Notification.
2014 Dec 12 13:01:50
Received From: (IIS8-5Server)
1.2.3.4->\inetpub\logs\LogFiles\W3SVC1\u_ex141212.log
Rule: 31153 fired (level 10) -> "Multiple common web attacks from same
souce ip."
Portion of the log(s):
2014-12-12 21:00:55 W3SVC1 IIS8-5Server 1.2.3.4 GET /cmd.exe - 443 -
2.3.4.5 HTTP/1.1
Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - -
IIS8-5Server 404 0 2 1477 256 0
On Friday, December 12, 2014 7:37:15 AM UTC-8, James Whittington wrote:
> I was just curious if anyone knew the status of the issue where IIS logs
> are not able to trigger on web_rules.xml?
>
> Basically even with a correct IIS decoder in place the web rules will
> never trigger.
>
>
>
> I came across some pretty obvious SQL Injection Attacks against IIS
> websites and was trying to determine why OSSEC didn’t catch those events.
>
>
>
> So really there is no point to running IIS logs through OSSEC if you can’t
> trigger against rules.
>
>
>
> I see the issue was raised here
> https://github.com/ossec/ossec-hids/issues/164
>
> With possible fix here https://github.com/ossec/ossec-hids/pull/434
>
>
>
> James Whittington
>
>
>
--
---
You received this message because you are subscribed to the Google Groups
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
For more options, visit https://groups.google.com/d/optout.