X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fvmware_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fvmware_rules.xml;h=1b49b508f3945e1578252fa9c69bae1525b9bba8;hp=0000000000000000000000000000000000000000;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/debian/ossec-hids/var/ossec/rules/vmware_rules.xml b/debian/ossec-hids/var/ossec/rules/vmware_rules.xml new file mode 100644 index 0000000..1b49b50 --- /dev/null +++ b/debian/ossec-hids/var/ossec/rules/vmware_rules.xml @@ -0,0 +1,157 @@ + + + + + + + vmware + VMWare messages grouped. + + + + vmware-syslog + VMWare ESX syslog messages grouped. + + + + 19100 + ^crit|^fatal + VMware ESX critical message. + + + + 19100 + ^error + VMware ESX error message. + + + + 19100 + ^warn + VMware ESX warning message. + + + + 19100 + ^notice + VMware ESX notice message. + + + + 19100 + ^info + VMware ESX informational message. + + + + 19100 + ^verbose + VMware ESX verbose message. + + + + + + + 19106 + logged in$ + VMWare ESX authentication success. + authentication_success, + + + + 19106 + Failed login attempt for + VMWare ESX authentication failure. + authentication_failed, + + + + 19101 + vmware-hostd|vmware-authd + Accepted password for|login from + VMWare ESX user login. + authentication_success, + + + + 19101 + vmware-hostd|vmware-authd + Rejected password for + VMWare ESX user authentication failure. + authentication_failed, + + + + + + 19106 + -> VM_STATE_OFF + Virtual machine state changed to OFF. + service_availability, + + + + 19106 + -> VM_STATE_POWERING_ON + Virtual machine being turned ON. + + + + 19106 + -> VM_STATE_ON + Virtual machine state changed to ON. + alert_by_email + + + + 19106 + -> VM_STATE_RECONFIGURING + Virtual machine being reconfigured. + config_changed, + alert_by_email + + + + + + + 19104 + Multiple VMWare ESX warning messages. + service_availability, + + + + 19103 + Multiple VMWare ESX error messages. + service_availability, + + + + 19111 + Multiple VMWare ESX authentication failures. + authentication_failures, + + + + 19113 + Multiple VMWare ESX user authentication failures. + authentication_failures, + + + + +