HI all,
I am trying to catch some Zeek events related to Zeek’s dhcp events, but it doesn’t seem to work:
<group name="zeek,ids,">
<rule id="66001" level="0">
<decoded_as>json</decoded_as>
<field name="ts">\.+</field>
<field name="uids">\.+</field>
<description>Zeek messages.</description>
<options>no_full_log</options>
</rule>
<rule id="66002" level=“3">
<if_sid>66001</if_sid>
<field name="host_name">^reykjavik$</field>
<description>Zeek: New IP address assigned to server reykjavik</description>
<options>no_full_log</options>
</rule>
</group>
An example event:
root@wazuh-master:~# wazuh-logtest
Starting wazuh-logtest v4.2.1
Type one log per line
{"ts":"2021-09-24T14:54:44.561249Z","uids":["CozBcK3aIh0y9OxKC2","CgG8oJ3LjU55ZjVEm8","CkQkNW3VbXJdJLFc85","CFs42s2aoKPI1BbHl8"],"client_addr":"172.22.55.4","server_addr":"172.22.55.1","mac":"a0:ce:c8:0a:7e:f4","host_name":"reykjavik","domain":"
lab.uxdom.org dmz.uxdom.org msft.uxdom.org","requested_addr":"172.22.55.4","assigned_addr":"172.22.55.4","lease_time":600.0,"msg_types":["OFFER","DISCOVER","OFFER","DISCOVER","REQUEST","REQUEST","ACK","ACK"],"duration":1.0148320198059083}
**Phase 1: Completed pre-decoding.
full event: '{"ts":"2021-09-24T14:54:44.561249Z","uids":["CozBcK3aIh0y9OxKC2","CgG8oJ3LjU55ZjVEm8","CkQkNW3VbXJdJLFc85","CFs42s2aoKPI1BbHl8"],"client_addr":"172.22.55.4","server_addr":"172.22.55.1","mac":"a0:ce:c8:0a:7e:f4","host_name":"reykjavik","domain":"
lab.uxdom.org dmz.uxdom.org msft.uxdom.org","requested_addr":"172.22.55.4","assigned_addr":"172.22.55.4","lease_time":600.0,"msg_types":["OFFER","DISCOVER","OFFER","DISCOVER","REQUEST","REQUEST","ACK","ACK"],"duration":1.0148320198059083}'
**Phase 2: Completed decoding.
name: 'json'
assigned_addr: '172.22.55.4'
client_addr: '172.22.55.4'
domain: '
lab.uxdom.org dmz.uxdom.org msft.uxdom.org'
duration: '1.014832'
host_name: 'reykjavik'
lease_time: '600'
mac: 'a0:ce:c8:0a:7e:f4'
msg_types: '['OFFER', 'DISCOVER', 'OFFER', 'DISCOVER', 'REQUEST', 'REQUEST', 'ACK', 'ACK']'
requested_addr: '172.22.55.4'
server_addr: '172.22.55.1'
ts: '2021-09-24T14:54:44.561249Z'
uids: '['CozBcK3aIh0y9OxKC2', 'CgG8oJ3LjU55ZjVEm8', 'CkQkNW3VbXJdJLFc85', 'CFs42s2aoKPI1BbHl8’]'
Where am I doing wrong?
Thanks.
Best regards,
C. L. Martinez