X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fopenbsd_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fopenbsd_rules.xml;h=6675e9e8b3d34af2e86a7a3992985b4aab331b08;hp=0000000000000000000000000000000000000000;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/debian/ossec-hids/var/ossec/rules/openbsd_rules.xml b/debian/ossec-hids/var/ossec/rules/openbsd_rules.xml new file mode 100644 index 0000000..6675e9e --- /dev/null +++ b/debian/ossec-hids/var/ossec/rules/openbsd_rules.xml @@ -0,0 +1,299 @@ + + + + + + + + + + bsd_kernel + Grouping of bsd_kernel alerts + + + + 51500 + ichiic0: abort failed, status 0x40 + A timeout occurred waiting for a transfer. + + + + 51500 + Check Condition (error 0x70) on opcode 0x0 + Check media in optical drive. + + + + 51500 + BBB bulk-in clear stall failed + A disk has timed out. + + + + 51500 + arp info overwritten for + arp info has been overwritten for a host + + + + 51500 + was not properly unmounted + A filesystem was not properly unmounted, likely system crash + + + + 51500 + UKC> quit + UKC was used, possibly modifying a kernel at boot time. + + + + 51500 + Michael MIC failure + Michael MIC failure: Checksum failure in the tkip protocol. + + + + 51500 + soft error (corrected) + A soft error has been corrected on a hard drive, + this is a possible early sign of failure. + + + + 51500 + acpithinkpad\d: + unknown event + Unknown acpithinkpad event + + + + 51500 + Critical temperature, shutting down + System shutdown due to temperature + + + + 51500 + _AL0[0] _PR0 failed + Unknown ACPI event (bug 6299 in OpenBSD bug tracking system). + + + + 51500 + ehci_freex: xfer=0xffff8000003ef800 not busy, 0x4f4e5155 + USB diagnostic message. + + + + 51500 + ichiic0: abort failed, status 0x0 + Possible APM or ACPI event. + + + + 51500 + Filesystem is not clean - run fsck + Unclean filesystem, run fsck. + + + + 51500 + atascsi_passthru_done, timeout + Timeout in atascsi_passthru_done. + + + + 51500 + RTC BIOS diagnostic error 80\pclock_battery\p + Clock battery error 80 + + + + 51500 + i/o error on block + I/O error on a storage device + + + + 51500 + kbc: cmd word write error + kbc error. + + + + 51500 + BBB reset failed, IOERROR + USB reset failed, IOERROR. + + + + groupdel + Grouping for groupdel rules. + groupdel, + + + + 51521 + group deleted + Group deleted. + groupdel, + + + + savecore + no core dump + No core dumps. + + + + reboot + rebooted by + System was rebooted. + + + + ^ftp-proxy + proxy cannot connect to server + ftp-proxy cannot connect to a server. + + + + bsd_kernel + uncorrectable data error reading fsbn + Hard drive is dying. + + + + bsd_kernel + ^carp + state transition + MASTER -> BACKUP + CARP master to backup. + + + + bsd_kernel + duplicate IP6 address + Duplicate IPv6 address. + + + + bsd_kernel + failed loadfirmware of file + Could not load a firmware. + + + + ^hotplugd + Permission denied$ + hotplugd could not open a file. + + + + open-userdel + user removed: name= + User account deleted. + account_changed, + + + + ntpd + bad peer from + Bad ntp peer. + + + + ^dhclient$ + 1002 + receive_packet failed on + dhclient receive_packet failed. + + + + 51533 + Input/output error$ + dhclient receive_packet failed due to I/O error. + + + + ^dhclient$ + 1002 + SIOCDIFADDR failed + SIOCDIFADDR failed + + + + 51535 + Device not configured$ + dhclient: device not configured. + + + + + + + + doas + doas grouping + + + + 51550 + cannot stat + doas cannot stat a file. + + + + 51551 + : Permission denied$ + doas cannot stat a file due to permissions. + + + + 51550 + path not secure$ + A critical path for doas does not have secure permissions. + + + + 51550 + failed command for + Failed doas command. + + + + 51550 + ran command + A command was run using doas. + + + + 51555 + as root + A doas command was run as root. + + + + 51550 + failed auth for + doas authentication failed. + + + + sendsyslog + ^dropped + sendsyslog dropped log messages. + + + + + +