X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fopenbsd_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fopenbsd_rules.xml;h=6675e9e8b3d34af2e86a7a3992985b4aab331b08;hp=0000000000000000000000000000000000000000;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b
diff --git a/debian/ossec-hids/var/ossec/rules/openbsd_rules.xml b/debian/ossec-hids/var/ossec/rules/openbsd_rules.xml
new file mode 100644
index 0000000..6675e9e
--- /dev/null
+++ b/debian/ossec-hids/var/ossec/rules/openbsd_rules.xml
@@ -0,0 +1,299 @@
+
+
+
+
+
+
+
+
+
+ bsd_kernel
+ Grouping of bsd_kernel alerts
+
+
+
+ 51500
+ ichiic0: abort failed, status 0x40
+ A timeout occurred waiting for a transfer.
+
+
+
+ 51500
+ Check Condition (error 0x70) on opcode 0x0
+ Check media in optical drive.
+
+
+
+ 51500
+ BBB bulk-in clear stall failed
+ A disk has timed out.
+
+
+
+ 51500
+ arp info overwritten for
+ arp info has been overwritten for a host
+
+
+
+ 51500
+ was not properly unmounted
+ A filesystem was not properly unmounted, likely system crash
+
+
+
+ 51500
+ UKC> quit
+ UKC was used, possibly modifying a kernel at boot time.
+
+
+
+ 51500
+ Michael MIC failure
+ Michael MIC failure: Checksum failure in the tkip protocol.
+
+
+
+ 51500
+ soft error (corrected)
+ A soft error has been corrected on a hard drive,
+ this is a possible early sign of failure.
+
+
+
+ 51500
+ acpithinkpad\d:
+ unknown event
+ Unknown acpithinkpad event
+
+
+
+ 51500
+ Critical temperature, shutting down
+ System shutdown due to temperature
+
+
+
+ 51500
+ _AL0[0] _PR0 failed
+ Unknown ACPI event (bug 6299 in OpenBSD bug tracking system).
+
+
+
+ 51500
+ ehci_freex: xfer=0xffff8000003ef800 not busy, 0x4f4e5155
+ USB diagnostic message.
+
+
+
+ 51500
+ ichiic0: abort failed, status 0x0
+ Possible APM or ACPI event.
+
+
+
+ 51500
+ Filesystem is not clean - run fsck
+ Unclean filesystem, run fsck.
+
+
+
+ 51500
+ atascsi_passthru_done, timeout
+ Timeout in atascsi_passthru_done.
+
+
+
+ 51500
+ RTC BIOS diagnostic error 80\pclock_battery\p
+ Clock battery error 80
+
+
+
+ 51500
+ i/o error on block
+ I/O error on a storage device
+
+
+
+ 51500
+ kbc: cmd word write error
+ kbc error.
+
+
+
+ 51500
+ BBB reset failed, IOERROR
+ USB reset failed, IOERROR.
+
+
+
+ groupdel
+ Grouping for groupdel rules.
+ groupdel,
+
+
+
+ 51521
+ group deleted
+ Group deleted.
+ groupdel,
+
+
+
+ savecore
+ no core dump
+ No core dumps.
+
+
+
+ reboot
+ rebooted by
+ System was rebooted.
+
+
+
+ ^ftp-proxy
+ proxy cannot connect to server
+ ftp-proxy cannot connect to a server.
+
+
+
+ bsd_kernel
+ uncorrectable data error reading fsbn
+ Hard drive is dying.
+
+
+
+ bsd_kernel
+ ^carp
+ state transition
+ MASTER -> BACKUP
+ CARP master to backup.
+
+
+
+ bsd_kernel
+ duplicate IP6 address
+ Duplicate IPv6 address.
+
+
+
+ bsd_kernel
+ failed loadfirmware of file
+ Could not load a firmware.
+
+
+
+ ^hotplugd
+ Permission denied$
+ hotplugd could not open a file.
+
+
+
+ open-userdel
+ user removed: name=
+ User account deleted.
+ account_changed,
+
+
+
+ ntpd
+ bad peer from
+ Bad ntp peer.
+
+
+
+ ^dhclient$
+ 1002
+ receive_packet failed on
+ dhclient receive_packet failed.
+
+
+
+ 51533
+ Input/output error$
+ dhclient receive_packet failed due to I/O error.
+
+
+
+ ^dhclient$
+ 1002
+ SIOCDIFADDR failed
+ SIOCDIFADDR failed
+
+
+
+ 51535
+ Device not configured$
+ dhclient: device not configured.
+
+
+
+
+
+
+
+ doas
+ doas grouping
+
+
+
+ 51550
+ cannot stat
+ doas cannot stat a file.
+
+
+
+ 51551
+ : Permission denied$
+ doas cannot stat a file due to permissions.
+
+
+
+ 51550
+ path not secure$
+ A critical path for doas does not have secure permissions.
+
+
+
+ 51550
+ failed command for
+ Failed doas command.
+
+
+
+ 51550
+ ran command
+ A command was run using doas.
+
+
+
+ 51555
+ as root
+ A doas command was run as root.
+
+
+
+ 51550
+ failed auth for
+ doas authentication failed.
+
+
+
+ sendsyslog
+ ^dropped
+ sendsyslog dropped log messages.
+
+
+
+
+
+