Jesus Here is the screenshot
[root@localhost filebeat]# cat /var/ossec/logs/alerts/alerts.json | grep '"001"'
{"timestamp":"2018-06-29T11:43:39.641+0200","rule":{"level":3,"description":"Ossec agent started.","id":"503","firedtimes":1,"mail":true,"groups":["ossec"],"pci_dss":["10.6.1","10.2.6"],"gpg13":["10.1"],"gdpr":["IV_35.7.d"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530265419.22597","cluster":{"name":"wazuh","node":"node01"},"full_log":"ossec: Agent started: 'Centos7_1->any'.","decoder":{"parent":"ossec","name":"ossec"},"data":{"data":"Centos7_1->any"},"location":"ossec"}
{"timestamp":"2018-06-29T11:43:39.641+0200","rule":{"level":7,"description":"Integrity checksum changed.","id":"550","firedtimes":1,"mail":false,"groups":["ossec","syscheck"],"pci_dss":["11.5"],"gpg13":["4.11"],"gdpr":["II_5.1.f"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530265419.22826","cluster":{"name":"wazuh","node":"node01"},"full_log":"Integrity checksum changed for: '/var/ossec/etc/ossec.conf'\nOld md5sum was: 'f2ba1b9b566d1003294980ae5ca347cc'\nNew md5sum is : 'ae4be0f3a65635d54e436ff90e3a821a'\nOld sha1sum was: 'f79b2b70f9356e3ac203ca85fb18ee132598050f'\nNew sha1sum is : '7b900b85cc291932cb6b29e23590cdeba5d2c744'\n","syscheck":{"path":"/var/ossec/etc/ossec.conf","size_after":"4889","perm_after":"100640","uid_after":"0","gid_after":"994","md5_before":"f2ba1b9b566d1003294980ae5ca347cc","md5_after":"ae4be0f3a65635d54e436ff90e3a821a","sha1_before":"f79b2b70f9356e3ac203ca85fb18ee132598050f","sha1_after":"7b900b85cc291932cb6b29e23590cdeba5d2c744","event":"modified"},"decoder":{"name":"syscheck_integrity_changed"},"location":"syscheck"}
{"timestamp":"2018-06-29T11:43:46.695+0200","rule":{"level":7,"description":"Listened ports status (netstat) changed (new port opened or closed).","id":"533","firedtimes":1,"mail":false,"groups":["ossec"],"pci_dss":["10.2.7","10.6.1"],"gpg13":["10.1"],"gdpr":["IV_35.7.d"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530265426.23577","cluster":{"name":"wazuh","node":"node01"},"previous_output":"ossec: output: 'netstat listening ports':\ntcp 0.0.0.0:22 0.0.0.0:* 1166/sshd\ntcp6 :::22 :::* 1166/sshd\ntcp 127.0.0.1:25 0.0.0.0:* 1329/master\ntcp6 ::1:25 :::* 1329/master\nudp 0.0.0.0:68 0.0.0.0:* 968/dhclient\ntcp 0.0.0.0:111 0.0.0.0:* 708/rpcbind\ntcp6 :::111 :::* 708/rpcbind\nudp 0.0.0.0:111 0.0.0.0:* 708/rpcbind\nudp6 :::111 :::* 708/rpcbind\nudp 127.0.0.1:323 0.0.0.0:* 727/chronyd\nudp6 ::1:323 :::* 727/chronyd\nudp 0.0.0.0:874 0.0.0.0:* 708/rpcbind\nudp6 :::874 :::* 708/rpcbind","full_log":"ossec: output: 'netstat listening ports':\ntcp 0.0.0.0:22 0.0.0.0:* 1161/sshd\ntcp6 :::22 :::* 1161/sshd\ntcp 127.0.0.1:25 0.0.0.0:* 1335/master\ntcp6 ::1:25 :::* 1335/master\nudp 0.0.0.0:68 0.0.0.0:* 965/dhclient\ntcp 0.0.0.0:111 0.0.0.0:* 710/rpcbind\ntcp6 :::111 :::* 710/rpcbind\nudp 0.0.0.0:111 0.0.0.0:* 710/rpcbind\nudp6 :::111 :::* 710/rpcbind\nudp 127.0.0.1:323 0.0.0.0:* 722/chronyd\nudp6 ::1:323 :::* 722/chronyd\nudp 0.0.0.0:872 0.0.0.0:* 710/rpcbind\nudp6 :::872 :::* 710/rpcbind","decoder":{"name":"ossec"},"previous_log":"ossec: output: 'netstat listening ports':\ntcp 0.0.0.0:22 0.0.0.0:* 1166/sshd\ntcp6 :::22 :::* 1166/sshd\ntcp 127.0.0.1:25 0.0.0.0:* 1329/master\ntcp6 ::1:25 :::* 1329/master\nudp 0.0.0.0:68 0.0.0.0:* 968/dhclient\ntcp 0.0.0.0:111 0.0.0.0:* 708/rpcbind\ntcp6 :::111 :::* 708/rpcbind\nudp 0.0.0.0:111 0.0.0.0:* 708/rpcbind\nudp6 :::111 :::* 708/rpcbind\nudp 127.0.0.1:323 0.0.0.0:* 727/chronyd\nudp6 ::1:323 :::* 727/chronyd\nudp 0.0.0.0:874 0.0.0.0:* 708/rpcbind\nudp6 :::874 :::* 708/rpcbind","location":"netstat listening ports"} {"timestamp":"2018-06-29T11:44:44.649+0200","rule":{"level":7,"description":"Integrity checksum changed.","id":"550","firedtimes":2,"mail":false,"groups":["ossec","syscheck"],"pci_dss":["11.5"],"gpg13":["4.11"],"gdpr":["II_5.1.f"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530265484.24803","cluster":{"name":"wazuh","node":"node01"},"full_log":"Integrity checksum changed for: '/etc/resolv.conf'\n","syscheck":{"path":"/etc/resolv.conf","size_after":"72","perm_after":"100644","uid_after":"0","gid_after":"0","md5_after":"56590de6241b8392a289a2ab6eb8d53c","sha1_after":"1e48093a39dc2cfa34ff49171036620258a9e76c","uname_after":"root","gname_after":"root","mtime_before":"2018-06-28T10:04:47","mtime_after":"2018-06-29T11:36:51","inode_before":17431959,"inode_after":17431966,"event":"modified"},"decoder":{"name":"syscheck_integrity_changed"},"location":"syscheck"}
{"timestamp":"2018-06-29T11:48:48.410+0200","rule":{"level":7,"description":"Integrity checksum changed.","id":"550","firedtimes":3,"mail":false,"groups":["ossec","syscheck"],"pci_dss":["11.5"],"gpg13":["4.11"],"gdpr":["II_5.1.f"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530265728.25341","cluster":{"name":"wazuh","node":"node01"},"full_log":"Integrity checksum changed for: '/etc/tuned/active_profile'\n","syscheck":{"path":"/etc/tuned/active_profile","size_after":"14","perm_after":"100644","uid_after":"0","gid_after":"0","md5_after":"9a561d913bcdb5a659ec2dd035975a8e","sha1_after":"633f07e1b5698d04352d5dca735869bf2fe77897","uname_after":"root","gname_after":"root","mtime_before":"2018-06-28T10:04:48","mtime_after":"2018-06-29T11:36:52","inode_after":50715186,"event":"modified"},"decoder":{"name":"syscheck_integrity_changed"},"location":"syscheck"}
{"timestamp":"2018-06-29T11:48:48.416+0200","rule":{"level":7,"description":"Integrity checksum changed.","id":"550","firedtimes":4,"mail":false,"groups":["ossec","syscheck"],"pci_dss":["11.5"],"gpg13":["4.11"],"gdpr":["II_5.1.f"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530265728.25877","cluster":{"name":"wazuh","node":"node01"},"full_log":"Integrity checksum changed for: '/etc/tuned/profile_mode'\n","syscheck":{"path":"/etc/tuned/profile_mode","size_after":"5","perm_after":"100644","uid_after":"0","gid_after":"0","md5_after":"451e20aff0f489cd2f7d4d73533aa961","sha1_after":"43683f4e92c48be4b00ddd86e011a4f27fcdbeb5","uname_after":"root","gname_after":"root","mtime_before":"2018-06-28T10:04:48","mtime_after":"2018-06-29T11:36:52","inode_after":50715073,"event":"modified"},"decoder":{"name":"syscheck_integrity_changed"},"location":"syscheck"}
{"timestamp":"2018-06-29T11:56:55.756+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":1,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.26408","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 3: Root can log in. File: /etc/ssh/sshd_config. Reference: 3 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 3: Root can log in.","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T11:56:55.759+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":2,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.26726","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 4: No Public Key authentication {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 4 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 4: No Public Key authentication","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T11:56:55.761+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":3,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.27086","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 5: Password Authentication {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 5 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 5: Password Authentication","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T11:56:55.764+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":4,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.27436","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 6: Empty passwords allowed {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 6 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 6: Empty passwords allowed","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T11:56:55.766+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":5,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.27786","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 7: Rhost or shost used for authentication {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 7 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 7: Rhost or shost used for authentication","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T11:56:55.768+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":6,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.28166","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 8: Wrong Grace Time {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 8 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 8: Wrong Grace Time","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T11:56:55.771+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":7,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.28502","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 9: Wrong Maximum number of authentication attempts {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 9 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 9: Wrong Maximum number of authentication attempts","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T11:56:55.773+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":8,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.28900","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - Testing against the CIS Red Hat Enterprise Linux 7 Benchmark v1.1.0. File: /etc/redhat-release. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - Testing against the CIS Red Hat Enterprise Linux 7 Benchmark v1.1.0.","file":"/etc/redhat-release"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.775+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":9,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.29391","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - Build considerations - Robust partition scheme - /tmp is not on its own partition. File: /etc/fstab. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - Build considerations - Robust partition scheme - /tmp is not on its own partition.","file":"/etc/fstab"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.778+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":10,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["1.1.5 RHEL7"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.29908","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - Build considerations - Robust partition scheme - /var is not on its own partition {CIS: 1.1.5 RHEL7}. File: /etc/fstab. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - Build considerations - Robust partition scheme - /var is not on its own partition","file":"/etc/fstab"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.780+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":11,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["4.1.2 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.30443","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.1.2 - Network parameters - IP send redirects enabled {CIS: 4.1.2 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/send_redirects. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.1.2 - Network parameters - IP send redirects enabled","file":"/proc/sys/net/ipv4/conf/all/send_redirects"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.783+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":12,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["1.1.1 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.31005","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.2.2 - Network parameters - ICMP redirects accepted {CIS: 1.1.1 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/accept_redirects. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.2.2 - Network parameters - ICMP redirects accepted","file":"/proc/sys/net/ipv4/conf/all/accept_redirects"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.785+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":13,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["4.2.3 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.31567","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.2.3 - Network parameters - ICMP secure redirects accepted {CIS: 4.2.3 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/secure_redirects. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.2.3 - Network parameters - ICMP secure redirects accepted","file":"/proc/sys/net/ipv4/conf/all/secure_redirects"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.787+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":14,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["4.2.4 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.32143","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.2.4 - Network parameters - martians not logged {CIS: 4.2.4 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/log_martians. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.2.4 - Network parameters - martians not logged","file":"/proc/sys/net/ipv4/conf/all/log_martians"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.789+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":15,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.32689","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 6.2.5 - SSH Configuration - Set SSH MaxAuthTries to 4 or Less {CIS - RHEL7 - 6.2.5} {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 6.2.5 - SSH Configuration - Set SSH MaxAuthTries to 4 or Less ","file":"/etc/ssh/sshd_config"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.792+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":16,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["6.2.8 RHEL7"],"pci_dss":["4.1"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.33226","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 6.2.8 - SSH Configuration - Root login allowed {CIS: 6.2.8 RHEL7} {PCI_DSS: 4.1}. File: /etc/ssh/sshd_config. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 6.2.8 - SSH Configuration - Root login allowed","file":"/etc/ssh/sshd_config"},"location":"rootcheck"} {"timestamp":"2018-06-29T11:56:55.794+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":17,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["6.2.9 RHEL7"],"pci_dss":["4.1"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530266215.33726","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 6.2.9 - SSH Configuration - Empty passwords permitted {CIS: 6.2.9 RHEL7} {PCI_DSS: 4.1}. File: /etc/ssh/sshd_config. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 6.2.9 - SSH Configuration - Empty passwords permitted","file":"/etc/ssh/sshd_config"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:06:33.536+0200","rule":{"level":3,"description":"PAM: Login session opened.","id":"5501","firedtimes":1,"mail":false,"groups":["pam","syslog","authentication_success"],"pci_dss":["10.2.5"],"gpg13":["7.8","7.9"],"gdpr":["IV_32.2"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530270393.34240","cluster":{"name":"wazuh","node":"node01"},"full_log":"Jun 29 13:06:31 localhost su: pam_unix(su:session): session opened for user root by root(uid=0)","predecoder":{"program_name":"su","timestamp":"Jun 29 13:06:31","hostname":"localhost"},"decoder":{"parent":"pam","name":"pam"},"data":{"srcuser":"root","dstuser":"root","uid":"0"},"location":"/var/log/secure"}
{"timestamp":"2018-06-29T13:28:12.575+0200","rule":{"level":3,"description":"Ossec agent started.","id":"503","firedtimes":1,"mail":true,"groups":["ossec"],"pci_dss":["10.6.1","10.2.6"],"gpg13":["10.1"],"gdpr":["IV_35.7.d"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530271692.34574","cluster":{"name":"wazuh","node":"node01"},"full_log":"ossec: Agent started: 'Centos7_1->any'.","decoder":{"parent":"ossec","name":"ossec"},"data":{"data":"Centos7_1->any"},"location":"ossec"}
{"timestamp":"2018-06-29T13:41:29.910+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":1,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.34803","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 3: Root can log in. File: /etc/ssh/sshd_config. Reference: 3 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 3: Root can log in.","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T13:41:29.912+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":2,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.35121","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 4: No Public Key authentication {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 4 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 4: No Public Key authentication","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T13:41:29.914+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":3,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.35481","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 5: Password Authentication {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 5 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 5: Password Authentication","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T13:41:29.917+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":4,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.35831","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 6: Empty passwords allowed {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 6 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 6: Empty passwords allowed","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T13:41:29.919+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":5,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.36181","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 7: Rhost or shost used for authentication {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 7 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 7: Rhost or shost used for authentication","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T13:41:29.922+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":6,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.36561","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 8: Wrong Grace Time {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 8 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 8: Wrong Grace Time","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T13:41:29.924+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":7,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.36897","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: SSH Hardening - 9: Wrong Maximum number of authentication attempts {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: 9 .","decoder":{"name":"rootcheck"},"data":{"title":"SSH Hardening - 9: Wrong Maximum number of authentication attempts","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}
{"timestamp":"2018-06-29T13:41:29.927+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":8,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.37295","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - Testing against the CIS Red Hat Enterprise Linux 7 Benchmark v1.1.0. File: /etc/redhat-release. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - Testing against the CIS Red Hat Enterprise Linux 7 Benchmark v1.1.0.","file":"/etc/redhat-release"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.929+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":9,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.37786","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - Build considerations - Robust partition scheme - /tmp is not on its own partition. File: /etc/fstab. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - Build considerations - Robust partition scheme - /tmp is not on its own partition.","file":"/etc/fstab"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.932+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":10,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["1.1.5 RHEL7"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.38303","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - Build considerations - Robust partition scheme - /var is not on its own partition {CIS: 1.1.5 RHEL7}. File: /etc/fstab. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - Build considerations - Robust partition scheme - /var is not on its own partition","file":"/etc/fstab"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.934+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":11,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["4.1.2 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.38838","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.1.2 - Network parameters - IP send redirects enabled {CIS: 4.1.2 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/send_redirects. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.1.2 - Network parameters - IP send redirects enabled","file":"/proc/sys/net/ipv4/conf/all/send_redirects"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.936+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":12,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["1.1.1 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.39400","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.2.2 - Network parameters - ICMP redirects accepted {CIS: 1.1.1 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/accept_redirects. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.2.2 - Network parameters - ICMP redirects accepted","file":"/proc/sys/net/ipv4/conf/all/accept_redirects"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.939+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":13,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["4.2.3 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.39962","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.2.3 - Network parameters - ICMP secure redirects accepted {CIS: 4.2.3 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/secure_redirects. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.2.3 - Network parameters - ICMP secure redirects accepted","file":"/proc/sys/net/ipv4/conf/all/secure_redirects"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.941+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":14,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["4.2.4 RHEL7"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.40538","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 4.2.4 - Network parameters - martians not logged {CIS: 4.2.4 RHEL7} {PCI_DSS: 2.2.4}. File: /proc/sys/net/ipv4/conf/all/log_martians. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 4.2.4 - Network parameters - martians not logged","file":"/proc/sys/net/ipv4/conf/all/log_martians"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.944+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":15,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"pci_dss":["2.2.4"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.41084","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 6.2.5 - SSH Configuration - Set SSH MaxAuthTries to 4 or Less {CIS - RHEL7 - 6.2.5} {PCI_DSS: 2.2.4}. File: /etc/ssh/sshd_config. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 6.2.5 - SSH Configuration - Set SSH MaxAuthTries to 4 or Less ","file":"/etc/ssh/sshd_config"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.946+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":16,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["6.2.8 RHEL7"],"pci_dss":["4.1"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.41621","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 6.2.8 - SSH Configuration - Root login allowed {CIS: 6.2.8 RHEL7} {PCI_DSS: 4.1}. File: /etc/ssh/sshd_config. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 6.2.8 - SSH Configuration - Root login allowed","file":"/etc/ssh/sshd_config"},"location":"rootcheck"} {"timestamp":"2018-06-29T13:41:29.948+0200","rule":{"level":3,"description":"System Audit event.","id":"516","firedtimes":17,"mail":false,"groups":["ossec","rootcheck"],"gdpr":["IV_30.1.g"],"cis":["6.2.9 RHEL7"],"pci_dss":["4.1"]},"agent":{"id":"001","name":"Centos7_1"},"manager":{"name":"localhost.localdomain"},"id":"1530272489.42121","cluster":{"name":"wazuh","node":"node01"},"full_log":"System Audit: CIS - RHEL7 - 6.2.9 - SSH Configuration - Empty passwords permitted {CIS: 6.2.9 RHEL7} {PCI_DSS: 4.1}. File: /etc/ssh/sshd_config. Reference: https://benchmarks.cisecurity.org/tools2/linux/CIS_Red_Hat_Enterprise_Linux_7_Benchmark_v1.1.0.pdf .","decoder":{"name":"rootcheck"},"data":{"title":"CIS - RHEL7 - 6.2.9 - SSH Configuration - Empty passwords permitted","file":"/etc/ssh/sshd_config"},"location":"rootcheck"}