X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;f=etc%2Frules%2Fsyslog_rules.xml;h=24b0b5fabda98b7353770b1c1bd2e62b54b52c36;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hp=80a00ee7d1a09de7d2c85ef184477ad3968278ad;hpb=6ef2f786c6c8ead94841b5f93baf9f43421f08c8;p=ossec-hids.git diff --git a/etc/rules/syslog_rules.xml b/etc/rules/syslog_rules.xml old mode 100755 new mode 100644 index 80a00ee..24b0b5f --- a/etc/rules/syslog_rules.xml +++ b/etc/rules/syslog_rules.xml @@ -18,7 +18,7 @@ -core_dumped|failure|error|attack|bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted +core_dumped|failure|error|attack| bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted @@ -72,6 +72,12 @@ PPM exceeds tolerance Ignoring known false positives on rule 1002.. + + + segfault at + Process segfaulted. + service_availability, + @@ -127,7 +133,8 @@ Authentication failed for|invalid password for| LOGIN FAILURE|auth failure: |authentication error| authinternal failed|Failed to authorize| - Wrong password given for|login failed|Auth: Login incorrect + Wrong password given for|login failed|Auth: Login incorrect| + Failed to authenticate user authentication_failed, User authentication failure. @@ -284,13 +291,13 @@ 5100 svc: unknown program 100227 (me 100003) - NFS incompability between Linux and Solaris. + NFS incompatibility between Linux and Solaris. 5100 svc: bad direction - NFS incompability between Linux and Solaris. + NFS incompatibility between Linux and Solaris. @@ -396,7 +403,7 @@ 5300 - authentication failure; |failed|BAD su|^-| - + authentication failure; |failed|BAD su|^- User missed the password to change UID (user id). authentication_failed, @@ -473,6 +480,13 @@ ^changed user Information from the user was changed + + + useradd + failed adding user + useradd failed. + + @@ -484,15 +498,15 @@ Initial group for sudo messages - + 5400 - 3 incorrect password attempts - Three failed attempts to run sudo + incorrect password attempt + Failed attempt to run sudo 5400 - ; USER=root ; COMMAND= + ; USER=root ; COMMAND=| ; USER=root ; TSID=\S+ ; COMMAND= Successful sudo to ROOT executed @@ -501,7 +515,20 @@ alert_by_email First time user executed sudo. - + + + + 5401 + 3 incorrect password attempts + Three failed attempts to run sudo + + + + 5400 + user NOT in sudoers + Unauthorized user attempted to use sudo. + + @@ -558,7 +585,15 @@ windows-date-format - ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d \w+ + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d startup | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d status | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d remove | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d configure | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d install | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d purge | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d trigproc | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d conffile | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d upgrade Dpkg (Debian Package) log. @@ -617,6 +652,73 @@ config_changed, Yum package deleted. + + + + 5100 + mptscsih + Grouping for the mptscrih rules. + + + + 5100 + mptbase + Grouping for the mptbase rules. + + + + 2935 + FAILED + Possible Disk failure. SCSI controller error. + + + + 2936 + failed + SCSI RAID ARRAY ERROR, drive failed. + + + + 2936 + degraded + SCSI RAID is now in a degraded status. + + + + ^NetworkManager + NetworkManager grouping. + + + + 2940 + No chain/target/match by that name.$ + Incorrect chain/target/match. + + + + 1002 + g_slice_set_config: assertion `sys_page_size == 0' failed + Uninteresting gnome error. + + + + ^nouveau + nouveau driver grouping + + + + 2943 + DATA_ERROR BEGIN_END_ACTIVE$| DATA_ERROR$ + Uninteresting nouveau error. + + + + ^rsyslogd + ^imuxsock begins to drop messages + https://isc.sans.edu/diary/Are+you+losing+system+logging+information+%28and+don%27t+know+it%29%3F/15106 + rsyslog may be dropping messages due to rate-limiting. + +