> Note To avoid partial matches, add a comma at the end of the group string. For example, <rules_group>group_a,|group_b,|group_c,</rules_group> Also, check that the rule group in your rule definitions ends with a comma as well. This is usually the case in the Wazuh default ruleset. For example, <group>group_b,</group>.
Not ending the group string with a comma implies that the group string is a substring open for partial matches. For example, the group string authentication matches rule groups authentication, authentication_success, and authentication_failure while the group string authentication, matches only rule group authentication.
> Note
When setting level, rules_group, and rules_id together, the active response will be triggered always that any rule matches with one of these options. In other words, they are accumulative options, not restrictive.
Thanks Nico,
Do I set integrator.debug=2 on the client /var/ossec/etc/internal_options.conf or the server?
What file does that log to?
Steve O'Brien | Senior Network Administrator
National Solar Observatory
Daniel K. Inouye Solar Telescope Project
22 Ohi’a Ku Street, Pukalani, HI 96768
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/QMmb5z8W63E/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/d06beb06-a799-4ce1-b4c4-4bc62681235en%40googlegroups.com.
Steve O'Brien | Senior Network Administrator
National Solar Observatory
Daniel K. Inouye Solar Telescope Project
22 Ohi’a Ku Street, Pukalani, HI 96768
Steve O'Brien | Senior Network Administrator
National Solar Observatory
Daniel K. Inouye Solar Telescope Project
22 Ohi’a Ku Street, Pukalani, HI 96768
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/c1e53a56-6f97-44a2-9704-b1c5f4a3edc5n%40googlegroups.com.