X-Git-Url: http://ftp.carnet.hr/pub/carnet-debian/scm?a=blobdiff_plain;f=etc%2Frules%2Fsyslog_rules.xml;h=24b0b5fabda98b7353770b1c1bd2e62b54b52c36;hb=HEAD;hp=06b61f649100952c5f927723041e70c5a5c25145;hpb=914feba5d54f979cd5d7e69c349c3d01f630042a;p=ossec-hids.git
diff --git a/etc/rules/syslog_rules.xml b/etc/rules/syslog_rules.xml
old mode 100755
new mode 100644
index 06b61f6..24b0b5f
--- a/etc/rules/syslog_rules.xml
+++ b/etc/rules/syslog_rules.xml
@@ -1,4 +1,4 @@
-
-core_dumped|failure|error|attack|bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted
+core_dumped|failure|error|attack| bad |illegal |denied|refused|unauthorized|fatal|failed|Segmentation Fault|Corrupted
@@ -59,6 +59,25 @@
File system full.
low_diskspace,
+
+
+ killed by SIGTERM
+ Process exiting (killed).
+ service_availability,
+
+
+
+ 1002
+ terminated without error|can't verify hostname: getaddrinfo|
+ PPM exceeds tolerance
+ Ignoring known false positives on rule 1002..
+
+
+
+ segfault at
+ Process segfaulted.
+ service_availability,
+
@@ -114,7 +133,8 @@
Authentication failed for|invalid password for|
LOGIN FAILURE|auth failure: |authentication error|
authinternal failed|Failed to authorize|
- Wrong password given for|login failed|Auth: Login incorrect
+ Wrong password given for|login failed|Auth: Login incorrect|
+ Failed to authenticate user
authentication_failed,
User authentication failure.
@@ -148,10 +168,47 @@
^Authentication passed
Pop3 Authentication passed.
+
+
+ openldap
+ OpenLDAP group.
+
+
+
+ 2507
+ ACCEPT from
+ OpenLDAP connection open.
+
+
+
+ 2507
+ 2508
+
+ RESULT tag=97 err=49
+ OpenLDAP authentication failed.
+
+
+
+
+
+ rshd
+ rshd messages grouped.
+
+
+
+ 2550
+ ^Connection from \S+ on illegal port$
+ Connection to rshd from unprivileged port. Possible network scan.
+ connection_attempt,
+
+
+
+
+
@@ -234,13 +291,13 @@
5100
svc: unknown program 100227 (me 100003)
- NFS incompability between Linux and Solaris.
+ NFS incompatibility between Linux and Solaris.
5100
svc: bad direction
- NFS incompability between Linux and Solaris.
+ NFS incompatibility between Linux and Solaris.
@@ -265,7 +322,7 @@
5100
- ipw2200: Firmware error detected.
+ ipw2200: Firmware error detected.| ACPI Error
Kernel device error.
@@ -346,7 +403,7 @@
5300
- authentication failure; |failed|BAD su|^-| -
+ authentication failure; |failed|BAD su|^-
User missed the password to change UID (user id).
authentication_failed,
@@ -380,6 +437,14 @@
alert_by_email
First time (su) is executed by user.
+
+
+ 5300
+ unknown class
+ OpenBSD uses login classes, and an inappropriate login class was used.
+ A user has attempted to su to an unknown class.
+
+
@@ -415,6 +480,13 @@
^changed user
Information from the user was changed
+
+
+ useradd
+ failed adding user
+ useradd failed.
+
+
@@ -426,15 +498,15 @@
Initial group for sudo messages
-
+
5400
- 3 incorrect password attempts
- Three failed attempts to run sudo
+ incorrect password attempt
+ Failed attempt to run sudo
5400
- ; USER=root ; COMMAND=
+ ; USER=root ; COMMAND=| ; USER=root ; TSID=\S+ ; COMMAND=
Successful sudo to ROOT executed
@@ -443,7 +515,20 @@
alert_by_email
First time user executed sudo.
-
+
+
+
+ 5401
+ 3 incorrect password attempts
+ Three failed attempts to run sudo
+
+
+
+ 5400
+ user NOT in sudoers
+ Unauthorized user attempted to use sudo.
+
+
@@ -458,7 +543,7 @@
9100
^GRE: \S+ from \S+ failed: status = -1
PPTPD failed message (communication error)
- poptop.sourceforge.net/dox/gre-protocol-unavailable.phtml
+ http://poptop.sourceforge.net/dox/gre-protocol-unavailable.phtml
@@ -500,7 +585,15 @@
windows-date-format
- ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d \w+
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d startup |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d status |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d remove |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d configure |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d install |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d purge |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d trigproc |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d conffile |
+ ^\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d upgrade
Dpkg (Debian Package) log.
@@ -559,6 +652,73 @@
config_changed,
Yum package deleted.
+
+
+
+ 5100
+ mptscsih
+ Grouping for the mptscrih rules.
+
+
+
+ 5100
+ mptbase
+ Grouping for the mptbase rules.
+
+
+
+ 2935
+ FAILED
+ Possible Disk failure. SCSI controller error.
+
+
+
+ 2936
+ failed
+ SCSI RAID ARRAY ERROR, drive failed.
+
+
+
+ 2936
+ degraded
+ SCSI RAID is now in a degraded status.
+
+
+
+ ^NetworkManager
+ NetworkManager grouping.
+
+
+
+ 2940
+ No chain/target/match by that name.$
+ Incorrect chain/target/match.
+
+
+
+ 1002
+ g_slice_set_config: assertion `sys_page_size == 0' failed
+ Uninteresting gnome error.
+
+
+
+ ^nouveau
+ nouveau driver grouping
+
+
+
+ 2943
+ DATA_ERROR BEGIN_END_ACTIVE$| DATA_ERROR$
+ Uninteresting nouveau error.
+
+
+
+ ^rsyslogd
+ ^imuxsock begins to drop messages
+ https://isc.sans.edu/diary/Are+you+losing+system+logging+information+%28and+don%27t+know+it%29%3F/15106
+ rsyslog may be dropping messages due to rate-limiting.
+
+