X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;f=etc%2Frules%2Fsyslog_rules.xml;h=24b0b5fabda98b7353770b1c1bd2e62b54b52c36;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hp=80a00ee7d1a09de7d2c85ef184477ad3968278ad;hpb=6ef2f786c6c8ead94841b5f93baf9f43421f08c8;p=ossec-hids.git
diff --git a/etc/rules/syslog_rules.xml b/etc/rules/syslog_rules.xml
old mode 100755
new mode 100644
index 80a00ee..24b0b5f
--- a/etc/rules/syslog_rules.xml
+++ b/etc/rules/syslog_rules.xml
@@ -18,7 +18,7 @@
-core_dumped|failure|error|attack|bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted
+core_dumped|failure|error|attack| bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted
@@ -72,6 +72,12 @@
PPM exceeds tolerance
Ignoring known false positives on rule 1002..
+
+
+ segfault at
+ Process segfaulted.
+ service_availability,
+
@@ -127,7 +133,8 @@
Authentication failed for|invalid password for|
LOGIN FAILURE|auth failure: |authentication error|
authinternal failed|Failed to authorize|
- Wrong password given for|login failed|Auth: Login incorrect
+ Wrong password given for|login failed|Auth: Login incorrect|
+ Failed to authenticate user
authentication_failed,
User authentication failure.
@@ -284,13 +291,13 @@
5100
svc: unknown program 100227 (me 100003)
- NFS incompability between Linux and Solaris.
+ NFS incompatibility between Linux and Solaris.
5100
svc: bad direction
- NFS incompability between Linux and Solaris.
+ NFS incompatibility between Linux and Solaris.
@@ -396,7 +403,7 @@
5300
- authentication failure; |failed|BAD su|^-| -
+ authentication failure; |failed|BAD su|^-
User missed the password to change UID (user id).
authentication_failed,
@@ -473,6 +480,13 @@
^changed user
Information from the user was changed
+
+
+ useradd
+ failed adding user
+ useradd failed.
+
+
@@ -484,15 +498,15 @@
Initial group for sudo messages
-
+
5400
- 3 incorrect password attempts
- Three failed attempts to run sudo
+ incorrect password attempt
+ Failed attempt to run sudo
5400
- ; USER=root ; COMMAND=
+ ; USER=root ; COMMAND=| ; USER=root ; TSID=\S+ ; COMMAND=
Successful sudo to ROOT executed
@@ -501,7 +515,20 @@
alert_by_email
First time user executed sudo.
-
+
+
+
+ 5401
+ 3 incorrect password attempts
+ Three failed attempts to run sudo
+
+
+
+ 5400
+ user NOT in sudoers
+ Unauthorized user attempted to use sudo.
+
+
@@ -558,7 +585,15 @@
windows-date-format
- ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d \w+
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d startup |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d status |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d remove |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d configure |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d install |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d purge |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d trigproc |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d conffile |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d upgrade
Dpkg (Debian Package) log.
@@ -617,6 +652,73 @@
config_changed,
Yum package deleted.
+
+
+
+ 5100
+ mptscsih
+ Grouping for the mptscrih rules.
+
+
+
+ 5100
+ mptbase
+ Grouping for the mptbase rules.
+
+
+
+ 2935
+ FAILED
+ Possible Disk failure. SCSI controller error.
+
+
+
+ 2936
+ failed
+ SCSI RAID ARRAY ERROR, drive failed.
+
+
+
+ 2936
+ degraded
+ SCSI RAID is now in a degraded status.
+
+
+
+ ^NetworkManager
+ NetworkManager grouping.
+
+
+
+ 2940
+ No chain/target/match by that name.$
+ Incorrect chain/target/match.
+
+
+
+ 1002
+ g_slice_set_config: assertion `sys_page_size == 0' failed
+ Uninteresting gnome error.
+
+
+
+ ^nouveau
+ nouveau driver grouping
+
+
+
+ 2943
+ DATA_ERROR BEGIN_END_ACTIVE$| DATA_ERROR$
+ Uninteresting nouveau error.
+
+
+
+ ^rsyslogd
+ ^imuxsock begins to drop messages
+ https://isc.sans.edu/diary/Are+you+losing+system+logging+information+%28and+don%27t+know+it%29%3F/15106
+ rsyslog may be dropping messages due to rate-limiting.
+
+