X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;f=etc%2Frules%2Fsyslog_rules.xml;h=24b0b5fabda98b7353770b1c1bd2e62b54b52c36;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hp=b536e438c59be8d6cf43230e51df8c0dcd56b0dd;hpb=301048b51990573e58a30dc4a5bb4ec285cad554;p=ossec-hids.git diff --git a/etc/rules/syslog_rules.xml b/etc/rules/syslog_rules.xml old mode 100755 new mode 100644 index b536e43..24b0b5f --- a/etc/rules/syslog_rules.xml +++ b/etc/rules/syslog_rules.xml @@ -1,4 +1,4 @@ - -core_dumped|failure|error|attack|bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted +core_dumped|failure|error|attack| bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted @@ -65,6 +65,19 @@ Process exiting (killed). service_availability, + + + 1002 + terminated without error|can't verify hostname: getaddrinfo| + PPM exceeds tolerance + Ignoring known false positives on rule 1002.. + + + + segfault at + Process segfaulted. + service_availability, + @@ -120,7 +133,8 @@ Authentication failed for|invalid password for| LOGIN FAILURE|auth failure: |authentication error| authinternal failed|Failed to authorize| - Wrong password given for|login failed|Auth: Login incorrect + Wrong password given for|login failed|Auth: Login incorrect| + Failed to authenticate user authentication_failed, User authentication failure. @@ -154,6 +168,26 @@ ^Authentication passed Pop3 Authentication passed. + + + openldap + OpenLDAP group. + + + + 2507 + ACCEPT from + OpenLDAP connection open. + + + + 2507 + 2508 + + RESULT tag=97 err=49 + OpenLDAP authentication failed. + + @@ -257,13 +291,13 @@ 5100 svc: unknown program 100227 (me 100003) - NFS incompability between Linux and Solaris. + NFS incompatibility between Linux and Solaris. 5100 svc: bad direction - NFS incompability between Linux and Solaris. + NFS incompatibility between Linux and Solaris. @@ -288,7 +322,7 @@ 5100 - ipw2200: Firmware error detected. + ipw2200: Firmware error detected.| ACPI Error Kernel device error. @@ -369,7 +403,7 @@ 5300 - authentication failure; |failed|BAD su|^-| - + authentication failure; |failed|BAD su|^- User missed the password to change UID (user id). authentication_failed, @@ -403,6 +437,14 @@ alert_by_email First time (su) is executed by user. + + + 5300 + unknown class + OpenBSD uses login classes, and an inappropriate login class was used. + A user has attempted to su to an unknown class. + + @@ -438,6 +480,13 @@ ^changed user Information from the user was changed + + + useradd + failed adding user + useradd failed. + + @@ -449,15 +498,15 @@ Initial group for sudo messages - + 5400 - 3 incorrect password attempts - Three failed attempts to run sudo + incorrect password attempt + Failed attempt to run sudo 5400 - ; USER=root ; COMMAND= + ; USER=root ; COMMAND=| ; USER=root ; TSID=\S+ ; COMMAND= Successful sudo to ROOT executed @@ -466,7 +515,20 @@ alert_by_email First time user executed sudo. - + + + + 5401 + 3 incorrect password attempts + Three failed attempts to run sudo + + + + 5400 + user NOT in sudoers + Unauthorized user attempted to use sudo. + + @@ -523,7 +585,15 @@ windows-date-format - ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d \w+ + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d startup | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d status | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d remove | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d configure | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d install | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d purge | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d trigproc | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d conffile | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d upgrade Dpkg (Debian Package) log. @@ -582,6 +652,73 @@ config_changed, Yum package deleted. + + + + 5100 + mptscsih + Grouping for the mptscrih rules. + + + + 5100 + mptbase + Grouping for the mptbase rules. + + + + 2935 + FAILED + Possible Disk failure. SCSI controller error. + + + + 2936 + failed + SCSI RAID ARRAY ERROR, drive failed. + + + + 2936 + degraded + SCSI RAID is now in a degraded status. + + + + ^NetworkManager + NetworkManager grouping. + + + + 2940 + No chain/target/match by that name.$ + Incorrect chain/target/match. + + + + 1002 + g_slice_set_config: assertion `sys_page_size == 0' failed + Uninteresting gnome error. + + + + ^nouveau + nouveau driver grouping + + + + 2943 + DATA_ERROR BEGIN_END_ACTIVE$| DATA_ERROR$ + Uninteresting nouveau error. + + + + ^rsyslogd + ^imuxsock begins to drop messages + https://isc.sans.edu/diary/Are+you+losing+system+logging+information+%28and+don%27t+know+it%29%3F/15106 + rsyslog may be dropping messages due to rate-limiting. + +