X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;ds=sidebyside;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fms_dhcp_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fms_dhcp_rules.xml;h=c0c8385f91a05b98fd33e48d3b30fbafe9d8a9e7;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hp=0000000000000000000000000000000000000000;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b;p=ossec-hids.git diff --git a/debian/ossec-hids/var/ossec/rules/ms_dhcp_rules.xml b/debian/ossec-hids/var/ossec/rules/ms_dhcp_rules.xml new file mode 100644 index 0000000..c0c8385 --- /dev/null +++ b/debian/ossec-hids/var/ossec/rules/ms_dhcp_rules.xml @@ -0,0 +1,436 @@ + + + + + + + + + + + + + ms-dhcp-ipv4 + Grouping for the MS-DHCP rules. + + + + 6300 + ^00 + The log was started. + service_start, + + + + 6300 + ^01 + The log was stopped. + service_availability, + + + + 6300 + ^02 + The log was temporarily paused due to low disk space. + system_error, + + + + 6300 + ^10 + A new IP address was leased to a client. + dhcp_lease_action, + + + + 6300 + ^11 + A lease was renewed by a client. + dhcp_lease_action, + + + + 6300 + ^12 + A lease was released by a client. + dhcp_lease_action, + + + + 6300 + ^13 + An IP address was found to be in use on the network. + dhcp_lease_action, + + + + 6300 + ^14 + A lease request could not be satisfied because the scope's address pool was exhausted. + service_availability,dhcp_lease_action, + + + + 6300 + ^15 + A lease was denied. + dhcp_lease_action, + + + + 6300 + ^16 + A lease was deleted. + dhcp_lease_action, + + + + 6300 + ^17 + A lease was expired and DNS records for an expired leases have not been deleted. + dhcp_lease_action, + + + + 6300 + ^18 + A lease was expired and DNS records were deleted. + dhcp_lease_action,dhcp_dns_maintenance + + + + 6300 + ^20 + A BOOTP address was leased to a client. + dhcp_lease_action, + + + + 6300 + ^21 + A dynamic BOOTP address was leased to a client. + dhcp_lease_action, + + + + + 6300 + ^22 + A BOOTP request could not be satisfied because the scope's address pool for BOOTP was exhausted. + dhcp_lease_action, + + + + 6300 + ^23 + A BOOTP IP address was deleted after checking to see it was not in use. + dhcp_lease_action, + + + + 6300 + ^24 + IP address cleanup operation has began. + dhcp_maintenance, + + + + 6300 + ^25 + IP address cleanup statistics. + dhcp_maintenance, + + + + 6300 + ^30 + DNS update request to the named DNS server. + dhcp_dns_maintenance, + + + + 6300 + ^31 + DNS update failed. + dhcp_dns_maintenance, + + + + 6300 + ^32 + DNS update successful. + dhcp_dns_maintenance, + + + + 6300 + ^33 + Packet dropped due to NAP policy. + dhcp_lease_action, + + + + + 6300 + ^5 + Codes above 50 are used for Rogue Server Detection information. + dhcp_rogue_server, + + + + + + + + + ms-dhcp-ipv6 + Grouping for the MS-DHCP rules. + + + + 6350 + ^11000 + Solicit. + dhcp_ipv6, + + + + 6350 + ^11001|^11002 + Advertise. + dhcp_ipv6, + + + + 6350 + ^11003 + Confirm. + dhcp_ipv6, + + + + 6350 + ^11004 + Renew. + dhcp_ipv6, + + + + 6350 + ^11005 + Rebind. + dhcp_ipv6, + + + + + 6350 + ^11006 + DHCP Decline. + dhcp_ipv6, + + + + 6350 + ^11007 + Release. + dhcp_ipv6, + + + + 6350 + ^11008 + Information Request. + dhcp_ipv6, + + + + 6350 + ^11009 + Scope Full. + dhcp_ipv6, + + + + 6350 + ^11010 + Started. + service_start, + + + + 6350 + ^11011 + Stopped. + service_availability, + + + + 6350 + ^11012 + Audit log paused. + service_availability, + + + + + 6350 + ^11013 + DHCP Log File. + system_error, + + + + 6350 + ^11014 + Bad Address. + dhcp_ipv6, + + + + 6350 + ^11015 + Address is already in use. + dhcp_ipv6, + + + + 6350 + ^11016 + Client deleted. + dhcp_ipv6, + + + + 6350 + ^11017 + DNS record not deleted. + dhcp_ipv6, + + + + 6350 + ^11018 + Expired. + dhcp_ipv6, + + + + 6350 + ^11019 + Expired and Deleted count. + dhcp_ipv6, + + + + 6350 + ^11020 + Database cleanup begin. + dhcp_ipv6, + + + + + 6350 + ^11021 + Database cleanup end. + dhcp_ipv6, + + + + 6350 + ^11023 + Service not authorized in AD. + dhcp_ipv6, + + + + 6350 + ^11024 + Service authorized in AD. + dhcp_ipv6, + + + + 6350 + ^11025 + Service has not determined if it is authorized in AD. + dhcp_ipv6, + + +