X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;f=etc%2Fdecoder.xml;h=1d73df8bdbacc766558eaa33661e6c65b3b126c7;hb=HEAD;hp=c809108565f180d0b87c71b69efa27a7b48bfea1;hpb=914feba5d54f979cd5d7e69c349c3d01f630042a;p=ossec-hids.git diff --git a/etc/decoder.xml b/etc/decoder.xml old mode 100755 new mode 100644 index c809108..1d73df8 --- a/etc/decoder.xml +++ b/etc/decoder.xml @@ -1,9 +1,9 @@ - - + (pam_unix)$ @@ -51,7 +52,7 @@ - ^pam_unix|^\(pam_unix\) + ^pam_unix|^\(pam_unix\)|^pam_succeed_if @@ -59,7 +60,15 @@ ^session \w+ ^for user (\S+) user - + + + pam @@ -68,6 +77,19 @@ srcip, user + + pam + ruser + ^=(\S+) + user + + + + pam + rhost=(\S+) + srcip + + pam rhost @@ -76,7 +98,6 @@ - @@ -132,6 +173,13 @@ name, user, location + + sshd + ^Postponed keyboard-interactive|^Failed keyboard-interactive + user (\S+) from (\S+) port (\d+) + user, srcip, srcport + + sshd ^Failed \S+ for invalid user|^Failed \S+ for illegal user @@ -142,7 +190,7 @@ sshd ^Failed \S+ - ^for (\S+) from (\S+) port \d+ \w+$ + ^for (\S+) from (\S+) port \d+ user, srcip @@ -153,17 +201,24 @@ user, srcip + + sshd + ^error: PAM: + user (\S+) from (\S+) + user, srcip + + sshd ^reverse mapping checking - ^\w+ for (\S+) + ^\w+ for \S+ [(\S+)] |^\w+ for (\S+) srcip - + sshd ^Invalid user|^Illegal user - from (\S+)$ + from (\S+) srcip @@ -174,20 +229,176 @@ srcip + + sshd + ^Received disconnect + ^from (\S+): |^from (\S+) + srcip + + + + sshd + ^Disconnected from invalid user + \S+ (\S+) + srcip + + + + sshd + ^Connection closed by + user (\S+) (\S+) + user, srcip + + + + sshd + ^Unable to negotiate with + ^(\S+) port (\d+) + srcip, srcport + + + + sshd + ^Protocol major versions differ for + ^(\S+) + srcip + + + + sshd - ^Did not receive identification|^Bad protocol version - from (\S+)$ + ^Did not receive identification |^Bad protocol version + from (\S+)$| from (\S+) port (\d+)$ + srcip,srcport + + + + sshd + ^refused connect + ^from (\S+)$|^from \S+ \((\S+\w+)\)$|^from \S+ \((\S+::)\)$ + srcip + + + + sshd + ^Connection closed + ^by (\S+)$ + srcip + + + + sshd + ^Received disconnect + ^from (\S+): + srcip + + + + + + sshd + ^pam_ldap: + user "uid=(\S+),ou=\w+,dc=\w+,dc=\w+" + user + + + + sshd + fatal: Unable to negotiate with + ^(\S+) port (\d+): |^(\S+): + srcip, srcport + + + + sshd + rhost=\S+\s+user=\S+ + rhost=(\S+)\s+user=(\S+) + srcip, user + + + + + + sshd + exceeded for + (\S+) from (\S+) port (\d+) + user, srcip, srcport + + + + + + ^dropbear + + + + + + dropbear + password + for '(\S+)' from (\S+):\d+$ + dstuser, srcip + + + + + + dropbear + nonexistent + from (\S+):\d+$ srcip + + + dropbear + (\S+) for '(\S+)' with key \S+ (\S+) from (\S+):\d+$ + status,dstuser,extra_data,srcip + + + ^rshd$ + + + + rshd + ^Connection from (\S+) on illegal port$ srcip + + ^cimserver$ + + + + cimserver + ^\w+: Authentication failed for user + ^(\S+).$ + user + + + + + @@ -230,10 +477,27 @@ smbd - from \((\d+.\d+.\d+.\d+)\) + from \((\S+)\) + srcip + + + + smbd + from (\S+)$ + from (\S+)$ + srcip + + + + smbd + to client \S+. + to client (\S+). srcip + + ^nmbd + ^sudo - ^\s+(\S+)\s: - user - name,user,location + ^\s*(\S+)\s:\sTTY=\S+\s;\sPWD=(\S+)\s;\sUSER=(\S+)\s;\sCOMMAND=(\.+)$| + ^\s*(\S+)\s:\sTTY=\S+\s;\sPWD=(\S+)\s;\sUSER=(\S+)\s;\sTSID=\S+\s;\sCOMMAND=(\.+)$ + dstuser,url,srcuser,status + name,dstuser,location First time user executed the sudo command - - + - + ^proftpd - proftpd + proftpd : Login successful ^\S+ \(\S+[(\S+)]\)\s*\S \w+ (\S+): Login successful @@ -353,7 +634,20 @@ pure-ftpd ^\((\S+)@(\S+)\) [ user,srcip - + + + + + + ^\S+ - \S+ [\d\d/\S\S\S/\d\d\d\d:\d\d:\d\d:\d\d \S\d\d\d\d] "\w+ \S+" + ^(\S+) - (\S+) [\d\d/\S\S\S/\d\d\d\d:\d\d:\d\d:\d\d -\d\d\d\d] "(\S+) (\.+) (\d+) \d+$ + extra_data,dstuser,action,url,status + + @@ -364,24 +658,65 @@ - Sun Jun 4 22:08:39 2006 [pid 21611] [dcid] OK LOGIN: Client "192.168.2.10" - Sun Jun 4 22:09:22 2006 [pid 21622] CONNECT: Client "192.168.2.10" - Sun Jun 4 22:09:24 2006 [pid 21621] [lalal] FAIL LOGIN: Client "192.168.2.10" - - Sat Jun 3 07:51:42 2006 [pid 25073] [Administrator] FAIL LOGIN: Client - "211.100.27.101" + - Sat Jun 3 07:51:42 2006 [pid 25073] [Administrator] FAIL LOGIN: Client "211.100.27.101" - Sun Aug 27 16:28:20 2006 [pid 13962] [xx] OK UPLOAD: Client "1.2.3.4", "/a.php", 8338 bytes, 18.77Kbyte/sec - Jul 13 12:31:20 www vsftpd: Sun Jul 13 10:31:20 2008 [pid 27528] [anonymous] FAIL LOGIN: Client "84.140.234.76" - --> + - Sun Aug 16 15:48:02 2015 [pid 4832] [ftpuser] OK DELETE: Client "172.28.5.129", "/index.php" + - Sun Aug 16 16:26:06 2015 [pid 4976] [ftpuser] OK CHMOD: Client "172.28.5.129", "/index.php 777" + - Sun Aug 16 16:26:21 2015 [pid 4976] [ftpuser] OK RENAME: Client "172.28.5.129", "/index.php /4444index.php" + ^\w\w\w \w\w\w\s+\d+ \S+ \d+ [pid \d+] - Client "(\d+.\d+.\d+.\d+)"$ + Client "(\S+)"$ srcip ^vsftpd ^\w\w\w \w\w\w\s+\d+ \S+ \d+ [pid \d+] - Client "(\d+.\d+.\d+.\d+)"$ + Client "(\S+)"$ srcip +--> + + + + + ^\w\w\w \w\w\w\s+\d+ \S+ \d+ [pid \d+] + + + + ^vsftpd + ^\w\w\w \w\w\w\s+\d+ \S+ \d+ [pid \d+] + + + + vsftpd + LOGIN: + [(\S+)] (\S+ LOGIN): Client "(\S+\w)"$ + user,status,srcip + + + + vsftpd + ^CONNECT: + (CONNECT): Client "(\S+\w+)"$ + action,srcip + + + vsftpd + [(\S+)] (OK \S+): Client "(\S+)", "(\.+)"\.* + user,status,srcip,url + + + + vsftpd + Client "(\S+\w)"$ + srcip + ^ftpd|^in.ftpd @@ -398,23 +734,31 @@ ftpd ^Failed authentication from: \S+ | ^repeated login failures from - [(\d+.\d+.\d+.\d+)]$ + + ^\S+ [(\S+)]$|^(\S+) srcip ftpd ^FTP LOGIN REFUSED - [(\d+.\d+.\d+.\d+)]$ + [(\S+)]$ srcip ftpd - from (\d+.\d+.\d+.\d+)$ + from (\S+)$ srcip + + ftpd + ^login \S+ from \S+ failed. + ^login (\S+) from (\S+) failed.$ + user, srcip + + ^arpwatch @@ -431,7 +777,7 @@ arpwatch ^new station |^bogon - ^(\d+.\d+.\d+.\d+) (\S+) + ^(\S+) (\S+) srcip, extra_data name, srcip, extra_data @@ -460,7 +806,7 @@ ^[\d\d\d\d-\d\d-\d\d \S+ \w+] ^\S+ (\w+): status - + @@ -471,11 +817,11 @@ - imapd[21040]: Login failed user=root domain=(null) auth=root host=host29-141.poo l8249.interbusiness.it [82.49.141.29] - imapd[27113]: Authenticated user=badyy host=a.resenet.com.br [1.2.3.4] - - imapd[27113]: Logout user=badyy host=a.resenet.com.br [1.2.3.4] + - imapd[27113]: Logout user=badyy host=a.resenet.com.br [1.2.3.4] --> ^imapd - user=(\S+) \.+ [(\d+.\d+.\d+.\d+)]$ + user=(\S+) \.+ [(\S+)]$ user,srcip @@ -483,10 +829,10 @@ @@ -496,28 +842,28 @@ vpopmail ^vchkpw-\S+: password fail - (\S+)@\S+:(\d+.\d+.\d+.\d+)$ + (\S+)@\S+:(\S+)$ user, srcip vpopmail ^vchkpw-\S+: vpopmail user not - ^found (\S+):(\d+.\d+.\d+.\d+)$ + ^found (\S+):(\S+)$ user, srcip vpopmail ^vchkpw-\S+: null password - ^given (\S+):(\d+.\d+.\d+.\d+)$ + ^given (\S+):(\S+)$ user, srcip vpopmail ^vchkpw-\S+: \(\S+\) login - ^success (\S+):(\d+.\d+.\d+.\d+)$ + ^success (\S+):(\S+)$ user, srcip @@ -534,7 +880,7 @@ vm-pop3d ^User ' ^(\S+)' - \w+ auth, - from=(\d+.\d+.\d+.\d+)$ + from=(\S+)$ user, srcip @@ -549,19 +895,19 @@ - Nov 24 18:18:28 gandalf pop3d: LOGIN FAILED, ip=[::ffff:1.2.3.4] --> - ^pop3d|^courierpop3login|^imaplogin + ^pop3d|^courierpop3login|^imaplogin|^courier-pop3|^courier-imap courier ^LOGIN, - ^user=(\S+), ip=[(\S+\d)]$ + ^user=(\S+), ip=[(\S+)]$ user, srcip courier - , ip=[(\S+\d)]$ + , ip=[(\S+)]$ srcip @@ -577,12 +923,16 @@ - dovecot: Jan 07 14:46:28 Warn: auth(default): userdb(username,::ffff:127.0.0.1): user not found from userdb - dovecot: Mar 13 15:25:07 Info: auth(default): pam(user@example.com,::ffff:1.2.3.4): pam_authenticate() failed: User not known to the underlying authentication module - dovecot: Mar 13 15:25:07 Info: auth(default): passwd-file(user@example.com,::ffff:1.2.3.4): unknown user - - Jan 11 03:45:09 hostname dovecot: auth-worker(default): sql(username,1.2.3.4): unknown user + - Jan 11 03:45:09 hostname dovecot: auth-worker(default): sql(username,1.2.3.4): unknown user - Jan 11 03:42:09 hostname dovecot: auth(default): pam(user@example.com,1.2.3.4): pam_authenticate() failed: User not known to the underlying authentication module - Jul 4 17:30:51 hostname dovecot[2992]: pop3-login: Disconnected: rip=1.2.3.4, lip=1.2.3.5 - dovecot: Jun 23 15:04:06 Info: IMAP(username): Disconnected: Logged out bytes=59/566 - dovecot: May 31 09:43:57 Info: pop3-login: Aborted login (1 authentication attempts): user=, method=PLAIN, rip=::ffff:1.2.3.4, lip=::ffff:1.2.3.5, secured - Jan 30 09:37:55 hostname dovecot: pop3-login: Aborted login: user=, method=PLAIN, rip=::ffff:1.2.3.4, lip=::ffff:1.2.3.5 + - Dec 19 17:40:57 ny dovecot: pop3-login: Disconnected (auth failed, 3 attempts in 51 secs): user=, method=PLAIN, rip=109.201.200.201, lip=67.205.141.203, session= + - Dec 19 17:30:39 ny dovecot: imap-login: Disconnected: Inactivity (auth failed, 7 attempts in 176 secs): user=<32>, method=PLAIN, rip=109.201.200.201, lip=67.205.141.203,session=<7QTLPAZEXrhtycjJ> + - Dec 19 17:38:54 ny dovecot: pop3-login: Disconnected: Inactivity during authentication (auth failed, 13 attempts in 179 secs): user=, method=PLAIN, rip=109.201.200.201, lip=67.205.141.203, session= + - Dec 19 17:20:08 ny dovecot: imap-login: Aborted login (auth failed, 2 attempts in 18 secs): user=, method=PLAIN, rip=109.201.200.201, lip=67.205.141.203, session= --> @@ -592,24 +942,54 @@ dovecot ^\w\w\w\w-login: Login: - ^user=\p(\S+)\p, method=\S+, rip=(\S+), - user, srcip + ^user=\p(\S+)\p, method=\S+, rip=(\S+), lip=(\S+), mpid=\S+, (\S*)$ + user, srcip, dstip, protocol dovecot ^\w\w\w\w-login: Aborted login - user=\p\S+>, method=\w+, rip=(\S+), lip=\S+ - srcip + : user=\p(\S+)\p, method=\S+, rip=(\S+), lip=(\S+), (\S*)$ + user, srcip, dstip, protocol + + + + dovecot + ^auth\(default\)|auth-worker\(default\) + ^: \S+\((\S+),(\S+)\) + user, srcip + + + + dovecot + ^\w\w\w\w-login: + \(auth failed, \d+ attempts in \d+ secs\): user=\p(\S+)\p, method=\w+, rip=(\S+), lip=(\S+) + user,srcip,dstip dovecot ^\w\w\w\w-login: Disconnected: - ^rip=(\S+), - srcip + ^rip=(\S+), lip=(\S+) + srcip, dstip + + + + ^Info$|^Warn$ + + + + dovecot-info + imap-login + Login: user=(\S+), method=\.+, rip=(\S+), lip=(\S+) + user, srcip, dstip + + dovecot-info + auth\(\.+\): \S+\((\S+),(\S+)\): + user, srcip + + - Oct 22 10:12:33 junction named[31687]: /etc/blocked.slave:9892: syntax error near ';' + - Oct 22 10:12:33 junction named[31687]: reloading configuration failed: unexpected token + --> ^named + + named + : query + client (\S+)#\d+\s*\S*: + srcip,url + + + + named + query: (\S+) IN|query \S+ '(\S+)/ + url + + - named + named ^client - ^(\d+.\d+.\d+.\d+)# + ^(\S+)# srcip named - from [(\d+.\d+.\d+.\d+)] + from [(\S+)] srcip + + named + for master + for master (\S+):(\d+) \S+ \(source (\S+)#d+\)$ + dstip,dstport,srcip + @@ -652,25 +1053,25 @@ true - postfix + postfix ^NOQUEUE: reject: \w\w\w\w from - [(\d+.\d+.\d+.\d+)]: (\d+) + [(\S+)]:\d+: (\d+) |[(\S+)]:(\d+): |[(\S+)]: (\d+) |[(\S+)]:(\d+): srcip,id - postfix + postfix ^warning: \S+: SASL - ^warning: \S+[(\d+.\d+.\d+.\d+)]: + ^warning: \S+[(\S+)]: srcip ^sendmail|^sm-mta|^sm-msp-queue - + sendmail-reject ^\S+: rejecting commands from - ^ \S+ [(\d+.\d+.\d+.\d+)] + ^ \S+ [(\S+)] srcip sendmail-reject relay=[ - ^(\d+.\d+.\d+.\d+)] + ^(\S+)] srcip sendmail-reject relay=\S+ [ - ^(\d+.\d+.\d+.\d+)] + ^(\S+)] srcip @@ -720,8 +1121,8 @@ ^smf-sav ^sender check failed| ^sender check tempfailed - ^ \(cached\): \S+, (\d+.\d+.\d+.\d+),| - ^: \S+, (\d+.\d+.\d+.\d+), + ^ \(cached\): \S+, (\S+),| + ^: \S+, (\S+), srcip @@ -730,12 +1131,12 @@ + + + ^smtpd + + + + smtpd + ^client + ^client (\S+) + srcip + + + + smtpd + relay= + relay=\S+ [(\S+)], + srcip + + + + smtpd + ^smtp-in: + ^(\S+) + status + + + + smtpd + => (\d+) + action + + + ^kernel - + iptables firewall ^[\d+.\d+] \S+ IN= - + ^[\d+.\d+] (\S+) \.+ SRC=(\S+) DST=(\S+) \.+ PROTO=(\w+) action,srcip,dstip,protocol @@ -792,7 +1227,7 @@ iptables firewall ^\S+ IN= - + ^(\S+) \.+ SRC=(\S+) DST=(\S+) \.+ PROTO=(\w+) action,srcip,dstip,protocol @@ -809,7 +1244,7 @@ iptables firewall ^Shorewall:\S+: - + ^(\S+):\.+ SRC=(\S+) DST=(\S+) \.+ PROTO=(\w+) action,srcip,dstip,protocol @@ -820,8 +1255,16 @@ firewall ^SPT=(\d+) DPT=(\d+) srcport,dstport - + + + iptables + firewall + ^\p\S+\p Shorewall:\S+: + ^(\S+):\.+ SRC=(\S+) DST=(\S+) \.+ + PROTO=(\w+) + action,srcip,dstip,protocol + firewall ^ipsec_logd - R:(\w) \w:\S+ S:(\d+.\d+.\d+.\d+) - D:(\d+.\d+.\d+.\d+) P:(\S+) SP:(\d+) DP:(\d+) + R:(\w) \w:\S+ S:(\S+) + D:(\S+) P:(\S+) SP:(\d+) DP:(\d+) action,srcip,dstip,protocol,srcport,dstport @@ -868,7 +1311,7 @@ - Mar 30 15:47:05.522341 rule 4/(match) block in on lo0: 127.0.0.1.48784 > 127.0.0.1.23: S 1381529123:1381529123(0) win 16384 (DF) [tos 0x10] - Mar 30 15:54:22.171929 rule 3/(match) pass out on xl0: 192.168.2.10.1514 > 192.168.2.190.1030: udp 73 - Mar 30 15:54:22.174412 rule 3/(match) pass out on xl0: 192.168.2.10.1514 > 192.168.2.190.1030: udp 89 - + --> firewall @@ -876,7 +1319,7 @@ PF_Decoder - + ^NetScreen device_id - + netscreenfw firewall - + system-notification-00257 \(traffic\): - + proto=(\w+) \.+action=(\w+) \.+src=(\S+) dst=(\S+) src_port=(\d+) dst_port=(\d+) protocol, action, srcip, dstip, srcport, dstport @@ -924,17 +1367,18 @@ netscreenfw system-critical-\.+ from | - system-alert-\.+ from - + system-alert-\.+ from | + system-emergency-\.+ From + system-(\w+)-(\d+): \.+ - from\.+(\d+.\d+.\d+.\d+) + from\.+(\S+) action, id, srcip netscreenfw system-(\w+)-(\d+): - action, id + action, id @@ -946,7 +1390,7 @@ - %PIX-3-106010: Deny inbound tcp src outside:213.98.79.233/2620 dst dmz:213.98.254.145/135 - %PIX-3-106011: Deny inbound (No xlate) udp src outside:192.168.2.1/137 dst outside:192.168.2.14/137 - - %PIX-3-106011: Deny inbound (No xlate) tcp src inside:10.100.7.43/80 dst + - %PIX-3-106011: Deny inbound (No xlate) tcp src inside:10.100.7.43/80 dst inside:10.100.4.71/2285 - %PIX-3-710003: TCP access denied by ACL from 216.39.220.130/54065 to outside:62.192.113.98/ssh - %PIX-7-710001: TCP access requested from X.X.X.X/1292 to outside:Y.Y.Y.Y/ssh @@ -956,7 +1400,7 @@ - %PIX-2-106002: udp connection denied by outbound list 30 src 216.53.120.62 138 dest 169.132.10.82 138 - %PIX-4-106023: Deny tcp src inside:111.11.11.1/2143 dst YYY:172.11.1.11/139 by access-group "inside_inbound" - %PIX-4-400013 IDS:2003 ICMP redirect from 10.4.1.2 to 10.2.1.1 on interface dmz - - %PIX-2-106006: Deny inbound UDP from ***/20031 to ***/20031 on + - %PIX-2-106006: Deny inbound UDP from ***/20031 to ***/20031 on interface vpn - %PIX-7-710002: TCP access permitted from 10.0.0.1/60749 to db:10.0.0.2/ssh - %PIX-6-305012: Teardown dynamic UDP translation from inside:1.1.1.1/12 to outside:1.2.1.2/11 duration 0:00:11. @@ -987,7 +1431,7 @@ pix firewall ^3-710003|^7-710002|^7-710005 - ^(\S+): (\S+) \w+ (\w+)\.+from + ^(\S+): (\S+) \w+ (\w+) \.+from (\S+)/(\S+) to \w+:(\S+)/(\S+) id, protocol, action, srcip, srcport, dstip, dstport @@ -1015,7 +1459,7 @@ firewall ^2-106006|^2-106007 ^(\S+): (\w+) \S+ (\w+) from - (\d+.\d+.\d+.\d+)/(\d+) to (\d+.\d+.\d+.\d+)/(\d+) + (\S+)/(\d+) to (\S+)/(\d+) id, action, protocol, srcip, srcport, dstip, dstport @@ -1046,23 +1490,47 @@ id, action, protocol, srcip, srcport, dstip, dstport + + pix + ^5-304001: + ^(\S+): (\S+) Accessed URL + (\S+):(http\w*://\.+)| + ^(\S+): (\S+) Accessed URL (\S+): + id, srcip, dstip, url + + + + pix + ^5-304002: + ^(\S+): Access (denied) URL (http\w*://\.+) + SRC (\S+) DEST (\S+) on interface + id, action, url, srcip, dstip + + pix ^2-106012: |^2-106017: | ^2-106020|^1-106021|^1-106022| ^4-4000 - ^(\S+): \.+ from (\d+.\d+.\d+.\d+) + ^(\S+): \.+ from (\S+) id, srcip pix - ^6-605004|^6-308001|^6-605005 - ^(\S+): \.+ (\d+.\d+.\d+.\d+) + ^6-308001 + ^(\S+): \.+ (\S+) id, srcip - + + pix + ^6-605004|^6-605005 + ^(\S+): Login (\S+) from (\S+)/(\d+) \.+user "(\w+)" + id, action, srcip, srcport, user + + + pix ^(\S+): id @@ -1071,7 +1539,7 @@ ^\d+ \d\d/\d\d/\d\d\d\d \S+ SEV=\d - ^(\S+) RPT=\d+ (\d+.\d+.\d+.\d+) + ^(\S+) RPT=\d+ (\S+) id, srcip - + @@ -1111,18 +1579,50 @@ ids ^[**] [\d+:\d+:\d+] - + snort ids ^[**] |^[\d+:\d+:\d+] - ^[**] [(\d+:\d+:\d+)] \.+ (\d+.\d+.\d+.\d+)\p*\d* -> - (\d+.\d+.\d+.\d+)|^[(\d+:\d+:\d+)] \.+ - (\d+.\d+.\d+.\d+)\p*\d* -> (\d+.\d+.\d+.\d+) + ^[**] [(\d+:\d+:\d+)] \.+ (\S+)\p*\d* -> + (\S+)|^[(\d+:\d+:\d+)] \.+ + (\S+)\p*\d* -> (\S+) id,srcip,dstip name,id,srcip,dstip + + snort + ids + ^[Drop] [**] |^[\d+:\d+:\d+] + ^[Drop] [**] [(\d+:\d+:\d+)] \.+ (\S+)\p*\d* -> + (\S+)|^[(\d+:\d+:\d+)] \.+ + (\S+)\p*\d* -> (\S+) + id,srcip,dstip + name,id,srcip,dstip + + + + + + + ^isakmpd + + + + isakmpd + message from + from (\S+) port (\d+) + srcip,srcport + + + + isakmpd + from peer + from peer (\S+):(\d+)$ + srcip,srcport + + ^suhosin ids - ^ALERT - (\.+) \(attacker '(\d+.\d+.\d+.\d+)', + ^ALERT - (\.+) \(attacker '(\S+)', id, srcip name, location, id @@ -1152,13 +1652,13 @@ ids ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d\| ^\S+\|(\S+)\| - (\d+.\d+.\d+.\d+)\|(\d+.\d+.\d+.\d+)\| + (\S+)\|(\S+)\| id, srcip, dstip name, id, srcip, dstip - - - + + + ^[\w+] [imp] |^[\w+] [horde] - + horde_imp ^Login success - ^for (\S+) [(\d+.\d+.\d+.\d+)] + ^for (\S+) [(\S+)] user, srcip horde_imp ^FAILED LOGIN - ^ (\d+.\d+.\d+.\d+) to \S+ as (\S+) + ^ (\S+) to \S+ as (\S+) srcip, user @@ -1190,11 +1690,12 @@ - Examples: - WPsyslog[14382]: [127.0.0.1 na] Info: User authentication failed. User name: lala - WPsyslog[14382]: [127.0.0.1 na] Info: User logged in. User name: admin (admin). + - wpcore[14554]: [127.0.0.1 na] http://megasite.com/wordpress Info: User authentication failed. User name: qwe. --> - ^WPsyslog + ^WPsyslog|^wpcore ^[ - ^(\d+.\d+.\d+.\d+) + ^(\S+) srcip @@ -1202,60 +1703,110 @@ + ^roundcube + + + ^[\d\d-\w\w\w-\d\d\d\d \d\d:\d\d:\d\d \S+] roundcube - ^: Successful login for - ^(\S+) \(id \d+\) from (\d+.\d+.\d+.\d+)$ + Successful login for + ^(\S+) \(id \d+\) from (\S+)$|^(\S+) \(ID: \d+\) from (\S+) user, srcip - + roundcube - ^ \w+ Error: Authentication - ^for (\.+) failed + ] \w+ Error: Authentication + ^for (\S+) failed user + + roundcube + > \w+ Error: Login failed |> Failed login + ^for (\S+) from (\S+)\. |^for (\S+) from (\S+) in session + user, srcip + + + - Without ID: Will extract the srcip and srcport (when it is available) + - [error] [client 80.230.208.105] Directory index forbidden by rule: /home/ + - [error] [client 64.94.163.159] Client sent malformed Host header + - [error] [client 66.31.142.16] File does not exist: /var/www/html/default.ida + - [Sun Nov 23 18:49:01.713508 2014] [:error] [pid 15816] [client 141.8.147.9:51507] PHP Notice: A non well formed numeric value encountered in /path/to/file.php on line 123 + - Feb 17 18:00:00 myhost httpd[18660]: [error] [client 12.34.56.78] File does not exist: /usr/local/htdocs/cache + - Feb 17 18:00:00 myhost httpd[23745]: [error] [client 12.34.56.78] PHP Notice: + - With IP + ID: Will extract the srcip, id, and srcport (when it is available) + - [Tue Sep 30 11:30:13.262255 2014] [core:error] [pid 20101] [client 99.47.227.95:34567] AH00037: Symbolic link not allowed or link target not accessible: /usr/share/awstats/icon/mime/document.png + - [Tue Sep 30 12:24:22.891366 2014] [proxy:warn] [pid 2331] [client 77.127.180.111:54082] AH01136: Unescaped URL path matched ProxyPass; ignoring unsafe nocanon, referer: http://www.easylinker.co.il/he/links.aspx?user=bguyb + - [Tue Sep 30 14:25:44.895897 2014] [authz_core:error] [pid 31858] [client 99.47.227.95:38870] AH01630: client denied by server configuration: /var/www/example.com/docroot/ + - [Thu Oct 23 15:17:55.926067 2014] [ssl:info] [pid 18838] [client 36.226.119.49:2359] AH02008: SSL library error 1 in handshake (server www.example.com:443) + - ModSecurity + - [Tue Feb 16 04:02:21.018764 2016] [:error] [pid 3223] [client 10.10.10.10] ModSecurity: Access denied with code 403 (phase 2). Text... + - [Tue Feb 16 04:02:21.018764 2016] [:error] [pid 3223] [client 10.10.10.10:5555] ModSecurity: Access denied with code 403 (phase 2). Text... + - Others + - [notice] Apache configured + - [Thu Oct 23 15:17:55.926123 2014] [ssl:info] [pid 18838] SSL Library Error: error:1407609B:SSL routines:SSL23_GET_CLIENT_HELLO:https proxy request -- speaking HTTP to HTTPS port!? + - [Tue Sep 30 12:11:21.258612 2014] [ssl:error] [pid 30473] AH02032: Hostname www.example.com provided via SNI and hostname ssl://www.example.com provided via HTTP are different +--> + - ^httpd - + ^httpd + - ^[warn] |^[notice] |^[error] - + ^[warn] |^[notice] |^[error] + - - apache-errorlog - - ^[client - ^ (\d+.\d+.\d+.\d+)] - srcip - + + ^[\w+ \w+ \d+ \d+:\d+:\d+.\d+ \d+] [\S+:warn] |^[\w+ \w+ \d+ \d+:\d+:\d+.\d+ \d+] [\S+:notice] |^[\w+ \w+ \d+ \d+:\d+:\d+.\d+ \d+] [\S*:error] |^[\w+ \w+ \d+ \d+:\d+:\d+.\d+ \d+] [\S+:info] + + + + + apache-errorlog + [client \S+:\d+] \S+: + [client (\S+):(\d+)] (\S+): + srcip,srcport,id + + + apache-errorlog + [client \S+] \S+: + [client (\S+)] (\S+): + srcip,id + + + + + apache-errorlog + [client + ^ (\S+):(\d+)] |^ (\S+)] + srcip,srcport + @@ -1272,7 +1823,7 @@ nginx-errorlog , client: \S+, server: \S+, request: "\S+ - , client: (\d+.\d+.\d+.\d+), + , client: (\S+), srcip @@ -1286,18 +1837,19 @@ - Examples: - 63.91.167.39 - - [03/Aug/2001:21:56:18 -0700] "GET /default.ida?NNNN - 206.78.62.16 - - [06/Aug/2001:08:57:08 -0700] "GET /default.ida?XX - - 5.211.112.6 - - [04/Feb/2003:16:17:30 -0500] "GET /mod_ssl:error: + - 5.211.112.6 - - [04/Feb/2003:16:17:30 -0500] "GET /mod_ssl:error: - 192.168.2.190 - - [18/Jan/2006:13:10:06 -0500] "GET /xxx.html HTTP/1.1" 200 1732 - - 1.1.1.1 - username [18/Jan/2006:13:10:06 -0500] "GET /xxx.html HTTP/1.1" + - 1.1.1.1 - username [18/Jan/2006:13:10:06 -0500] "GET /xxx.html HTTP/1.1" - 123.4.5.6 aa.xx.com - [05/Nov/2006:00:46:56 -0500] "GET / HTTP/1.1" 302 - + - ::ffff:202.194.15.192 190.7.138.180 - [18/Oct/2010:10:48:55 -0500] "GET //php-my-admin/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 345 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)" --> web-log - ^\d+.\d+.\d+.\d+ - ^(\d+.\d+.\d+.\d+) \S+ \S+ [\S+ \S\d+] - "\w+ (\S+) HTTP\S+ (\d+) - srcip, url, id + ^\S+ \S+ \S+ [\S+ \S\d+] "\w+ \S+ HTTP\S+" + ^(\S+) \S+ (\S+) [\S+ \S\d+] + "(\w+) (\S+) HTTP\S+" (\d+) + srcip, srcuser, action, url, id @@ -1310,7 +1862,7 @@ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d - + + + + windows-date-format + web-log + true + ^\S+ GET |^\S+ POST + (\S+ \S*) \.* (\S+) \S*\.* (\d\d\d) \S+ \S+ \S+ + url,srcip,id + + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d: @@ -1413,9 +1986,9 @@ racoon true - + ^ERROR: couldn't find the pskey - ^for (\d+.\d+.\d+.\d+) + ^for (\S+) srcip @@ -1425,50 +1998,60 @@ action - - - - - squid - ^\d+ \d+.\d+.\d+.\d+ - ^\d+ (\d+.\d+.\d+.\d+) (\w+)/(\d+) \d+ \w+ (\S+) - srcip,action,id,url - windows - ^WinEvtLog: - ^\.+: (\w+)\((\d+)\): (\.+): + ^WinEvtLog + + + + windows + windows + ^\.+: (\w+)\((\d+)\): (\.+): (\.+): \.+: (\S+): status, id, extra_data, user, system_name - name, location, user, system_name - + name, location, system_name + + + + windows + windows + Source Network Address: (\S+) + srcip + + + + windows + windows + Account Name:\s+(\w+\.+)\s+Account + user + + + + windows + windows + Account Domain:\s\s+(\w\.+)\s\s+Logon ID: + extra_data + windows - ^MSWinEventLog\t\d\t\.+\t\d+\t\w\w\w \w\w\w \d\d \d\d + ^MSWinEventLog\t\d\t\.+\t\d+\t\w\w\S+ \w\w\w \d\d \d\d ^:\d\d:\d\d \d\d\d\d\t(\d+)\t(\.+) \t(\.+)\t\.+\t(\.+)\t(\.+)\t id, extra_data, user, status, system_name @@ -1571,23 +2154,49 @@ ^ossec: ossec - + + + + ossec + ^\d\d\d\d/\d\d/\d\d \d\d:\d\d:\d\d ossec-logcollector + ^\(\d+\): (\.) + extra_data + ossec ossec ^Agent started: - ^ '(\S+)' + ^ '(\S+\S)' extra_data name, location, extra_data + + ossec + ^ossec: Alert Level: + OSSECAlert_Decoder + + ^ossec$ OSSECAlert_Decoder - + + + + + ^\w\w\w \w+\s+\d+ \d\d:\d\d:\d\d \w+ \d+ /\S+/active-response + /bin/(\S+) (\S+) - (\S+) (\d+.\d+) (\d+) + action, status, srcip, id, extra_data + ^[\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d.\d\d\d '\S+' \d+ - + vmware ^(\w+)] \S+ \S+ status - + vmware - ^: User (\w+)@(\d+.\d+.\d+.\d+) - logged |^: Failed login \w+ for (\w+)@(\d+.\d+.\d+.\d+) + ^: User (\w+)@(\S+) + logged |^: Failed login \w+ for (\w+)@(\S+) user, srcip - + vmware @@ -1640,7 +2249,7 @@ ^ \S+ for user (\S+) from (\S+)$ user, srcip - + vmware-syslog ^login from @@ -1657,7 +2266,7 @@ - Nov 21 15:16:22 unknown audit: [ID 984917 audit.notice] login - telnet failed session 2740580090 by root as root:root from 1.254.168.192 - failed session 2740580090 by root as root:root from 1.254.168.192 - - ok session 347344759 by 500959152 as root:root from 3.11.8.4 obj + - ok session 347344759 by 500959152 as root:root from 3.11.8.4 obj --> ^audit$ @@ -1689,14 +2298,40 @@ ^asterisk + + asterisk + ^WARNING[\d+]: \S+ in \S+: Don't know + ^\S+ how to respond via '(\w+/\d.\d/\w+)' + user + + asterisk ^NOTICE[\d+]: \S+ in \S+: Registration from - ^\S+ failed for '(\d+.\d+.\d+.\d+)' - srcip + ^'\.+' failed for '(\S+):(\d+)'|^'\.+' failed for '(\S+)' + srcip,srcport + + asterisk + Registration from + failed for '(\S+):(\d+)'|failed for '(\S+)' + srcip,srcport + + + + asterisk + ^NOTICE[\d+][\w+]: \S+ in \S+: Call from + ^'\S*' \((\S+):(\d+)\) to extension '(\S+)' rejected because extension not found in context '(\S+)'.$ + srcip, srcport, extra_data, extra_data + + + asterisk + ^NOTICE[\d+]: \S+ in \S+: Host + ^(\S+) failed MD5 authentication for (\S+) + srcip, user + - + ^Checkpoint ^\s+\S+ \d\d:\d\d:\d\d @@ -1823,9 +2458,9 @@ in HTTP request too long; attack: Malformed HTTP; src: 10.10.10.4; dst: firewall ^drop|^accept|^reject ^(\w+)\s+\S+ \p\S+ rule:\.+ - src: (\d+.\d+.\d+.\d+); dst: (\d+.\d+.\d+.\d+); proto: (\S+); + src: (\S+); dst: (\S+); proto: (\S+); action,srcip,dstip,protocol - + checkpoint-syslog @@ -1833,13 +2468,13 @@ in HTTP request too long; attack: Malformed HTTP; src: 10.10.10.4; dst: service: (\d+); s_port: (\d+); dstport,srcport - + checkpoint-syslog ids ^monitor|^drop attack: (\.+); - src: (\d+.\d+.\d+.\d+); dst: (\d+.\d+.\d+.\d+); + src: (\S+); dst: (\S+); proto: (\S+); extra_data, srcip, dstip, protocol name, extra_data, srcip, dstip @@ -1851,7 +2486,7 @@ in HTTP request too long; attack: Malformed HTTP; src: 10.10.10.4; dst: - + - ^\d\d,\d+/\d+/\d\d\d\d,\d+:\d+:\d+, - ^(\d\d), - id + ^\d\d,\d+/\d+/\d\d\d\d,\d+:\d+:\d+,| + ^\d\d,\d+/\d+/\d\d,\d+:\d+:\d+, + ^(\d\d),\d+/\d+/\d\d\d*,\d+:\d+:\d+,(\w+),(\S+) + id,extra_data,srcip -11020,05/05/09,00:00:38,DHCPV6 ^\d\d\d\d\d,\d\d/\d\d/\d\d,\d\d:\d\d:\d\d, ^(\d\d\d\d\d), @@ -1877,5 +2512,860 @@ in HTTP request too long; attack: Malformed HTTP; src: 10.10.10.4; dst: + + + ^/bsd + + + + bsd_kernel + ^arp + for (\S+) by (\S+) on \S+ + dstip, extra_data + + + + + + userdel + user removed: name=(\S+)$ + srcuser + + + + + + + + ^mountd + + + + mountd + from host + (\S+) port \d+$ + srcip + + + + + + + + + + + groupdel + ^group deleted: name=(\S+)$ + extra_data + + + + + + ^portsentry + + + + portsentry + attackalert: Connect from host: + (\S+)/\S+ to (\S+) port: (\d+)$ + srcip,protocol,dstport + + + + portsentry + is already blocked. Ignoring$ + Host: (\S+) is + srcip + + + + + + ^clamd + + + + ^freshclam + + + + + + ^slapd + + + + + openldap + ACCEPT + ^conn=(\d+) fd=\d+ ACCEPT from IP=(\S+): + id, srcip + + + + + openldap + BIND + ^conn=(\d+) op=\d+ BIND dn="\w+=(\w+), + id, dstuser + + + + + + openldap + RESULT + ^conn=(\d+) op=\d+ RESULT + id + + + + + ^ntpd + + + + ntpd + ^bad peer + ^bad peer \S+ \p(\S+)\p$|^bad peer from pool \S+ \p(\S+)\p$ + srcip + + + + +type=USER_ACCT msg=audit(1310592861.936:1222): user pid=24675 uid=0 auid=501 ses=188 subj=system_u:system_r:unconfined_t:s0 msg='op=PAM:accounting acct="username" exe="/usr/bin/sudo" (hostname=?, addr=?, terminal=pts/5 res=success)' +type=CRED_ACQ msg=audit(1305666154.831:51859): user pid=21250 uid=0 auid=4294967295 subj=system_u:system_r:unconfined_t:s0-s0:c0.c1023 msg='PAM: setcred acct="username" : exe="/usr/sbin/sshd" (hostname=lala.example.com, addr=172.16.0.1, terminal=ssh res=success)' +type=CRED_ACQ msg=audit(1273182001.226:148635): user pid=29770 uid=0 auid=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='PAM: setcred acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron +type=USER_AUTH msg=audit(1305666163.690:51871): user pid=21269 uid=0 auid=500 subj=user_u:system_r:unconfined_t:s0 msg='PAM: authentication acct="root" : exe="/bin/su" (hostname=?, addr=?, terminal=pts/0 res=success)' +type=USER_ACCT msg=audit(1306939201.750:67934): user pid=4401 uid=0 auid=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='PAM: accounting acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron res=success)' +type=CRED_ACQ msg=audit(1306939201.751:67935): user pid=4401 uid=0 auid=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='PAM: setcred acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron res=success)' +type=USER_START msg=audit(1306939201.756:67937): user pid=4401 uid=0 auid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='PAM: session open acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron res=success)' +type=USER_CHAUTHTOK msg=audit(1304523288.952:37394): user pid=7258 uid=0 auid=500 subj=user_u:system_r:unconfined_t:s0 msg='op=change password id=505 exe="/usr/bin/passwd" (hostname=?, addr=?, terminal=pts/1 res=success)' + + +type=USER_ACCT msg=audit(1310592861.936:1222): user pid=24675 uid=0 auid=501 ses=188 subj=system_u:system_r:unconfined_t:s0 msg='op=PAM:accounting acct="username" exe="/usr/bin/sudo" (hostname=?, addr=?, terminal=pts/5 res=success)' + + +type=SYSCALL msg=audit(1307045440.943:148): arch=c000003e syscall=59 success=yes exit=0 a0=de1fa8 a1=de23a8 a2=dc3008 a3=7fff1db3cc60 items=2 ppid=11719 pid=12140 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts8 ses=4294967295 comm="wget" exe="/tmp/wget" key="webserver-watch-tmp" +type=SYSCALL msg=audit(1307045820.403:151): arch=c000003e syscall=59 success=no exit=-13 a0=de24c8 a1=de2408 a2=dc3008 a3=7fff1db3cc60 items=1 ppid=11719 pid=12347 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts8 ses=4294967295 comm="bash" exe="/bin/bash" key=(null) +type=SYSCALL msg=audit(1306939143.715:67933): arch=40000003 syscall=94 success=yes exit=0 a0=5 a1=180 a2=8ebd360 a3=8ec4978 items=1 ppid=4383 pid=4388 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=8038 comm="less" exe="/usr/bin/less" subj=user_u:system_r:unconfined_t:s0 key="perm_mod" +type=USER_ROLE_CHANGE msg=audit(1280266360.845:51): user pid=1978 uid=0 auid=500 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=user_u:system_r:unconfined_t:s0 selected-context=user_u:system_r:unconfined_t:s0: exe="/bin/login" (hostname=?, addr=?, terminal=tty1 res=success)' +type=PATH msg=audit(1306967989.163:119): item=0 name="./ls" inode=261813 dev=fb:00 mode=0100755 ouid=0 ogid=0 rdev=00:00 + + +type=PATH msg=audit(1273924468.947:179534): item=0 name=(null) inode=424783 dev=fd:07 mode=0100640 ouid=0 ogid=502 rdev=00:00 obj=user_u:object_r:file_t:s0 + +--> + + + ^type= + + + + + auditd + ^AVC + ^(AVC) msg=audit\(\d\d\d\d\d\d\d\d\d\d.\d\d\d:(\d+)\): avc: (\S+) { \.+ } for pid=\d+ comm="(\S+)" path="\S+" dev=\S+ ino=\d+ scontext=\S+ tcontext=\S+ tclass=\S+$ + action,id,status,extra_data + + + + + auditd + ^SYSCALL + ^(SYSCALL) msg=audit\(\d\d\d\d\d\d\d\d\d\d.\d\d\d:(\d+)\): arch=\w+ syscall=\d+ success=(\S+) exit=\S+ a0=\w+ a1=\w+ a2=\w+ a3=\w+ items=\d+ ppid=\d+ pid=\d+ auid=\d+ uid=\d+ gid=\d+ euid=\d+ suid=\d+ fsuid=\d+ egid=\d+ sgid=\d+ fsgid=\d+ tty=\S+ ses=\d+ comm="\S+" exe="(\.+)" + action,id,status,extra_data + + + + + auditd + ^CONFIG_CHANGE + ^(CONFIG_CHANGE) msg=audit\(\d\d\d\d\d\d\d\d\d\d.\d\d\d:(\d+)\): auid=\d+ ses=\d+ op="\.+" path="(\.+)" key="\S+" list=\d+ res=\d+$ + action,id,extra_data + + + + + auditd + ^PATH + ^(PATH) msg=audit\(\d\d\d\d\d\d\d\d\d\d.\d\d\d:(\d+)\): item=\d+ name="(\.+)" inode=\d+ dev=\S+ mode=\d+ ouid=\d+ ogid=\d+ rdev=\S+ + action,id,extra_data + + + + + auditd + ^(USER_\S+) msg=audit\(\d\d\d\d\d\d\d\d\d\d.\d\d\d:(\d+)\): user pid=\d+ uid=\d+ auid=\d+| + ^(CRED_\S+) msg=audit\(\d\d\d\d\d\d\d\d\d\d.\d\d\d:(\d+)\): user pid=\d+ uid=\d+ auid=\d+ + action,id + + + + auditd + acct="(\.+)" : exe="(\.+)" \(hostname=\S+, addr=(\S+), terminal=\S+$ + user,extra_data,srcip + + + + auditd + ses=\d+ subj=\S+ msg='\.+ acct="(\.+)" exe="(\.+)" hostname=\S+ addr=(\S+) terminal=\S+ res=(\S+)$ + user,extra_data,srcip,status + + + + auditd + subj=\S+ msg='\.+ acct="(\.+)" \p*\s*exe="(\.+)" \(hostname=\S+, addr=(\S+), terminal=\S+ res=(\S+)\)'$ + user,extra_data,srcip,status + + + + auditd + subj=\S+ msg='\.+ exe="(\.+)" \(hostname=\S+, addr=(\S+), terminal=\S+ res=(\S+)\)'$ + extra_data,srcip,status + + + + + iptables + ^[\s\d+.\d+] mptscsih: + ^[\s\d+.\d+] (\w+): (\w+): task abort: (\w+) + id,data,status + + + + iptables + ^[\s\d+.\d+] mptbase: + ^[\s\d+.\d+] (\w+): (\w+):\s+\w+ is now (\w+)\p\s(\D+)$ + id,data,action,status + + + + + + + + ^HT286: [\w\w:\w\w:\w\w:\w\w:\w\w:\w\w]\p*\.+\p* | + ^HT502: [\w\w:\w\w:\w\w:\w\w:\w\w:\w\w]\p*\.+\p* | + ^HT503: [\w\w:\w\w:\w\w:\w\w:\w\w:\w\w]\p*\.+\p* + + + + grandstream-ata + Received + ^(\d+) response for transaction (\d+)\((\w+)\)$ + status, id, action + + + + grandstream-ata + Account + ^(\d+) (registered), tried \d+; Next registration in \d+ seconds \(\d+/\d+\) on (\.+)$ + id, status, extra_data + name, location, extra_data + + + + grandstream-ata + Vinetic:: + ^(startRing) with CID, Attempting to deliver CID (\d+) on port \d+$ + action, id + + + + grandstream-ata + ^(Dialing) (\d+)$ + action, id + + + + + + + iptables + apparmor= + apparmor="(\S+)" operation="(\S+)" + status, extra_data + + + + + ^unix_chkpwd + + + + + unix_chkpwd + user \((\w+)\)$ + srcuser + + + + + + ^inbound/pass|^scan|^outbound/smtp + + + + barracuda-svf-email + ^\S+[\S+]| + ^\S+ + ^\S+[(\S+)] (\d+-\w+-\w+) \d+ \d+ | + ^(\S+) (\d+-\w+-\w+) \d+ \d+ + srcip, id + + + + + barracuda-svf-email + (SCAN) (\S+ \S+ \S+ \S+ \d+ \d+ \.+ SUBJ:\.+)$ + action, extra_data + + + + + barracuda-svf-email + (RECV) (\S+ \S+ \d+ \d+ \.+)$ + action, extra_data + + + + + barracuda-svf-email + (SEND) (\S+ \d+ \S+ \.+)$ + action, extra_data + + + + + + ^web + + + + barracuda-svf-admin + ^[\S+] global[] CHANGE + ^[(\S+)] global[] (CHANGE) (\S+ \(\S*)\)$ + srcip,action,extra_data + + + + barracuda-svf-admin + ^[\S+] LOGIN| + ^[\S+] FAILED_LOGIN| + ^[\S+] LOGOUT + ^[(\S+)] (\S+) \((\S+)\)\p*$ + srcip,action,user + + + + + + +windows +INFORMATION\(1\) +Image: (\.*) \s*CommandLine: \.* \s*User: (\.*) \s*LogonGuid: \S* \s*LogonId: \S* \s*TerminalSessionId: \S* \s*IntegrityLevel: \.*HashType: \S* \s*Hash: (\S*) \s*ParentProcessGuid: \S* \s*ParentProcessID: \S* \s*ParentImage: (\.*) \s*ParentCommandLine: +status,user,url,data + + + + + squid + ^\d+ \S+ + ^\d+ (\S+) (\w+)/(\d+) \d+ \w+ (\S+) + srcip,action,id,url + + + + + + + ^unbound + + + + unbound + info: (\S+) (\S+). A IN$| info: (\S+) (\S+) AAAA IN$ + srcip,url + + + + + ^doas + + + + doas + ^(\S+) ran| for (\S+): + srcuser + + + + doas + as (\S+): + dstuser + + + + + + windows-date-format + authenticator failed + [(\S+)]:\d+: \d+ Incorrect authentication data \(set_id=(\w+)\) + srcip,user + + + + windows-date-format + ^SMTP connection from + [(\S+)]:\d+ \(TCP/IP connection count + srcip + + + + windows-date-format + ^SMTP connection from + [(\S+)]:\d+ lost + srcip + + + + windows-date-format + ^SMTP call from + [(\S+)]:\d+ dropped: too many syntax or protocol errors + srcip + + + + + + ^nsd + + + + nsd + from (\S+)@| from (\S+) + srcip + + + + + + ^{"reqId":"\S+","message":"\.+","level":\d,"time":"\.+"}$|^{"app":"\S+","message":"\.+","level":\d,"time":"\.+"}$|^{"reqId":"\S+","level":\d,"time":"\S+","message":"\.+"}$ + + + + + ^ownCloud + + + + owncloud + Login failed: user + ^'(\w+)' , wrong password, IP:(\d+.\d+.\d+.\d+) + user, srcip + + + + owncloud + Login failed: + ^'(\w+)' \(Remote IP: '(\d+.\d+.\d+.\d+) + user, srcip + + + + owncloud + Passed filename is not valid, might be malicious + ;ip:"(\d+.\d+.\d+.\d+)|;ip:\\"(\d+.\d+.\d+.\d+) + srcip + + + + owncloud + ","level": + ^(\d)," + status + + + + + + psad + + + + psad + ^scan detected + (\S+) -> (\S+) \.+ DL: (\d) + srcip,dstip,status + + + + psad + ^message repeated + (\S+) -> (\S+) \.+ DL: (\d) + srcip,dstip,status + + + + psad + signature match: + src: (\S+) signature match: \.+ port: (\d+) + srcip,dstport + + + + + + ^pvedaemon + + + + ^pvestatd + + + + ^pveproxy + + + + ^pvepw-logger + + + + pvedaemon + authentication failure; + ^rhost=(\S+) user=(\S+)@pam msg=|^rhost=(\S+) user=(\S+)@pve msg= + srcip, user + + + + pvedaemon + successful auth for user ' + ^(\S+)@pam'$|^(\S+)@pve'$ + user + + + + ^dhcpd$ + + + + dhcpd + ^(\S+) \S+ (\S+) \S+ (\S+) via (\S+)$ + action, srcip, extra_data, extra_data + + + + dhcpd + acking + already acking lease (\S+) + srcip + + + + dhcpd + ^IP address + ^IP address (\S+) + srcip + + + + + [\d+/\w+/\d+:\d+:\d+:\d+ -\d+] " + ^(\S+) (\S+) \S+ \S+ [\d+/\w+/\d+:\d+:\d+:\d+ -\d+] "(\S+) (\S+) HTTP/\d.\d" (\d+) \d$ + url, srcip, protocol, url, status + web-log + + + + + + ^dnsmasq + + + + dnsmasq + ^[\d+]: \d+ (\S+)/\d+ (\S+) (\S+) to (\S+)| + ^[\d+]: \d+ (\S+)/\d+ (\S+) (\S+) from (\S+)| + ^[\d+]: \d+ (\S+)/\d+ (\S+) (\S+) is (\S+) + srcip, action, url, extra_data + + + + + + + + + + + + + + + + ^kesl + + + + kesl + ^\p\pEventType\p: \p\S+\p,\pEventId\p: \p\d+\p,\pTaskName\p: \p\S+\p,\pTaskId\p: \p\d+\p,\pAVBasesDate\p: \p\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d\p\p + ^\p\pEventType\p: \p(\S+)\p,\pEventId\p: \p(\d+)\p,\pTaskName\p: \p(\S+)\p,\pTaskId\p: \p\d+\p,\pAVBasesDate\p: \p(\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d)\p\p + status, id, action, extra_data + + + + kesl + ^\p\pEventType\p: \p\S+\p,\pEventID\p: \p\d+\p,\pDetectName\p: \p\S+\p,\pDetectType\p: \p\S+\p,\pDetectCertainty\p: \p\S+\p,\pDetectSource\p: \p\S+\p,\pFileName\p: \p\S+,\pObjectName\p: \p\S+\p,\pTaskId\p: \p\d+\p,\pRuntimeTaskId\p: \p\d+\p,\pTaskName\p: \p\S+\p,\pTaskType\p: \p\S+\p,\pAccessUser\p: \p\S+\p,\pAccessUserId\p: \p\d+\p,\pFileOwner\p: \p\S+\p,\pFileOwnerId\p: \p\d+\p\p + ^\p\pEventType\p: \p(\S+)\p,\pEventID\p: \p(\d+)\p,\pDetectName\p: \p\S+\p,\pDetectType\p: \p\S+\p,\pDetectCertainty\p: \p(\S+)\p,\pDetectSource\p: \p\S+\p,\pFileName\p: \S+,\pObjectName\p: \p\S+\p,\pTaskId\p: \p\d+\p,\pRuntimeTaskId\p: \p\d+\p,\pTaskName\p: \p\S+\p,\pTaskType\p: \p(\S+)\p,\pAccessUser\p: \p\S+\p,\pAccessUserId\p: \p\d+\p,\pFileOwner\p: \p\S+\p,\pFileOwnerId\p: \p\d+\p\p + status, id, extra_data, action + + + + kesl + ^\p\pEventType\p: \p\S+\p,\pEventId\p: \p\d+\p,\pTaskName\p: \p\S+\p,\pTaskType\p: \p\S+\p,\pTaskId\p: \p\d+\p,\pTaskState\p: \p\S+\p,\pPrevTaskState\p: \p\S+\p,\pTaskRequestInitiator\p: \p\S+\p,\pRuntimeTaskId\p: \p\d+\p\p + ^\p\pEventType\p: \p(\S+)\p,\pEventId\p: \p(\d+)\p,\pTaskName\p: \p\S+\p,\pTaskType\p: \p(\S+)\p,\pTaskId\p: \p\d+\p,\pTaskState\p: \p(\S+)\p,\pPrevTaskState\p: \p\S+\p,\pTaskRequestInitiator\p: \p(\S+)\p,\pRuntimeTaskId\p: \p\d+\p\p + action, id, extra_data, status, srcuser + + + + + + + dionaea.connections + ^{\pdirection\p: \p(\S+)\p, \pprotocol\p: \p(\S+)\p, \pids_type\p: \p\S+\p, \ptimestamp\p: \p\d\d\d\d-\d\d-\d\d\w\d\d:\d\d:\d\d\.\d+\p, \pdionaea_action\p: \p(\S+)\p, \ptype\p: \pdionaea.connections\p, \papp\p: \pdionaea\p, \psrc_ip\p: "(\S+)", \pvendor_product\p: \pDionaea\p, \pdest_port\p: (\d+), \psignature\p: \p\.+\p, \psrc_port\p: (\d+), \pdest_ip\p: "(\S+)", \psensor\p: \S+, \ptransport\p: \p\S+\p, \pseverity\p: \p\S+\p} + extra_data, protocol, action, srcip, dstport, srcport, dstip + + + + + + + + + + cowrie.sessions + + + + cowrie + "SSH login attempted + ^{\pdirection\p: \p\S+\p, \pprotocol\p: \p(\S+)\p, \pids_type\p: \p(\S+)\p, \pssh_username\p: \p(\S+)\p, \papp\p: \pcowrie\p, \ptransport\p: \p\S+\p, \pdest_port\p: (\d+), \psrc_port\p: (\d+), \pseverity\p: \p\S+\p, \ptimestamp\p: \p\d\d\d\d-\d\d-\d\d\w\d\d:\d\d:\d\d.\d+\p, \pvendor_product\p: \pCowrie\p, \psensor\p: \S+, \psrc_ip\p: "(\S+)", \pssh_password\p: \p\S+\p, \psignature\p: \p(\.+)\p, \pssh_version\p: \.+, \ptype\p: \pcowrie.sessions\p, \pdest_ip\p: "(\S+)"} + protocol, extra_data, user, dstport, srcport, srcip, action, dstip + + + + cowrie + "SSH session on cowrie honeypot + ^{\pdirection\p: \p\S+\p, \pprotocol\p: \p(\S+)\p, \pids_type\p: \p(\S+)\p, \ptimestamp\p: \p\d\d\d\d-\d\d-\d\d\w\d\d:\d\d:\d\d.\d+\p, \pvendor_product\p: \pCowrie\p, \ptype\p: \pcowrie.sessions\p, \papp\p: \pcowrie\p, \psrc_ip\p: "(\S+)", \pdest_port\p: (\d+), \psignature\p: \p(\.+)\p, \pssh_version\p: \.+, \psrc_port\p: (\d+), \pdest_ip\p: "(\S+)", \psensor\p: \S+, \ptransport\p: \p\S+\p, \pseverity\p: \p\S+\p} + protocol, extra_data, srcip, dstport, action, srcport, dstip + + + + cowrie + "command attempted on cowrie honeypot + ^{\pdirection\p: \p\S+\p, \pprotocol\p: \p(\S+)\p, \pids_type\p: \p(\S+)\p, \ptimestamp\p: \p\d\d\d\d-\d\d-\d\d\w\d\d:\d\d:\d\d.\d+\p, \papp\p: \pcowrie\p, \ptransport\p: \p\S+\p, \pdest_port\p: (\d+), \psrc_port\p: (\d+), \pseverity\p: \p\S+\p, \pvendor_product\p: \pCowrie\p, \psensor\p: \S+, \psrc_ip\p: "(\S+)", \pcommand\p: \p\S+\p, \psignature\p: \p(\.+)\p, \pssh_version\p: \.+, \ptype\p: \pcowrie.sessions\p, \pdest_ip\p: "(\S+)"} + protocol, extra_data, dstport, srcport, srcip, action, dstip +