X-Git-Url: http://ftp.carnet.hr/pub/carnet-debian/scm?a=blobdiff_plain;f=etc%2Frules%2Fsyslog_rules.xml;h=24b0b5fabda98b7353770b1c1bd2e62b54b52c36;hb=HEAD;hp=06b61f649100952c5f927723041e70c5a5c25145;hpb=914feba5d54f979cd5d7e69c349c3d01f630042a;p=ossec-hids.git diff --git a/etc/rules/syslog_rules.xml b/etc/rules/syslog_rules.xml old mode 100755 new mode 100644 index 06b61f6..24b0b5f --- a/etc/rules/syslog_rules.xml +++ b/etc/rules/syslog_rules.xml @@ -1,4 +1,4 @@ - -core_dumped|failure|error|attack|bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted +core_dumped|failure|error|attack| bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted @@ -59,6 +59,25 @@ File system full. low_diskspace, + + + killed by SIGTERM + Process exiting (killed). + service_availability, + + + + 1002 + terminated without error|can't verify hostname: getaddrinfo| + PPM exceeds tolerance + Ignoring known false positives on rule 1002.. + + + + segfault at + Process segfaulted. + service_availability, + @@ -114,7 +133,8 @@ Authentication failed for|invalid password for| LOGIN FAILURE|auth failure: |authentication error| authinternal failed|Failed to authorize| - Wrong password given for|login failed|Auth: Login incorrect + Wrong password given for|login failed|Auth: Login incorrect| + Failed to authenticate user authentication_failed, User authentication failure. @@ -148,10 +168,47 @@ ^Authentication passed Pop3 Authentication passed. + + + openldap + OpenLDAP group. + + + + 2507 + ACCEPT from + OpenLDAP connection open. + + + + 2507 + 2508 + + RESULT tag=97 err=49 + OpenLDAP authentication failed. + + + + + + rshd + rshd messages grouped. + + + + 2550 + ^Connection from \S+ on illegal port$ + Connection to rshd from unprivileged port. Possible network scan. + connection_attempt, + + + + + @@ -234,13 +291,13 @@ 5100 svc: unknown program 100227 (me 100003) - NFS incompability between Linux and Solaris. + NFS incompatibility between Linux and Solaris. 5100 svc: bad direction - NFS incompability between Linux and Solaris. + NFS incompatibility between Linux and Solaris. @@ -265,7 +322,7 @@ 5100 - ipw2200: Firmware error detected. + ipw2200: Firmware error detected.| ACPI Error Kernel device error. @@ -346,7 +403,7 @@ 5300 - authentication failure; |failed|BAD su|^-| - + authentication failure; |failed|BAD su|^- User missed the password to change UID (user id). authentication_failed, @@ -380,6 +437,14 @@ alert_by_email First time (su) is executed by user. + + + 5300 + unknown class + OpenBSD uses login classes, and an inappropriate login class was used. + A user has attempted to su to an unknown class. + + @@ -415,6 +480,13 @@ ^changed user Information from the user was changed + + + useradd + failed adding user + useradd failed. + + @@ -426,15 +498,15 @@ Initial group for sudo messages - + 5400 - 3 incorrect password attempts - Three failed attempts to run sudo + incorrect password attempt + Failed attempt to run sudo 5400 - ; USER=root ; COMMAND= + ; USER=root ; COMMAND=| ; USER=root ; TSID=\S+ ; COMMAND= Successful sudo to ROOT executed @@ -443,7 +515,20 @@ alert_by_email First time user executed sudo. - + + + + 5401 + 3 incorrect password attempts + Three failed attempts to run sudo + + + + 5400 + user NOT in sudoers + Unauthorized user attempted to use sudo. + + @@ -458,7 +543,7 @@ 9100 ^GRE: \S+ from \S+ failed: status = -1 PPTPD failed message (communication error) - poptop.sourceforge.net/dox/gre-protocol-unavailable.phtml + http://poptop.sourceforge.net/dox/gre-protocol-unavailable.phtml @@ -500,7 +585,15 @@ windows-date-format - ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d \w+ + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d startup | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d status | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d remove | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d configure | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d install | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d purge | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d trigproc | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d conffile | + ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d upgrade Dpkg (Debian Package) log. @@ -559,6 +652,73 @@ config_changed, Yum package deleted. + + + + 5100 + mptscsih + Grouping for the mptscrih rules. + + + + 5100 + mptbase + Grouping for the mptbase rules. + + + + 2935 + FAILED + Possible Disk failure. SCSI controller error. + + + + 2936 + failed + SCSI RAID ARRAY ERROR, drive failed. + + + + 2936 + degraded + SCSI RAID is now in a degraded status. + + + + ^NetworkManager + NetworkManager grouping. + + + + 2940 + No chain/target/match by that name.$ + Incorrect chain/target/match. + + + + 1002 + g_slice_set_config: assertion `sys_page_size == 0' failed + Uninteresting gnome error. + + + + ^nouveau + nouveau driver grouping + + + + 2943 + DATA_ERROR BEGIN_END_ACTIVE$| DATA_ERROR$ + Uninteresting nouveau error. + + + + ^rsyslogd + ^imuxsock begins to drop messages + https://isc.sans.edu/diary/Are+you+losing+system+logging+information+%28and+don%27t+know+it%29%3F/15106 + rsyslog may be dropping messages due to rate-limiting. + +