--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ecafd6cf-9ab7-4db2-9167-9c12862cac49%40googlegroups.com.
id=firewall sn=xxxxxxxx time=\"2020-04-13 10:56:34\" fw=x.x.x.x pri=6 c=1024 gcat=6 m=537 msg=\"Connection Closed\" src=x.x.x.x:51053:X2 srcZone=Encrypted dst=x.x.x.x:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule=\"70 (VPN->LAN)\" vpnpolicy=\"TOI have runt\" app=49178 appName='General HTTPS MGMT' n=408226 fw_action=\"NA\" dpi=0
id=firewall sn=xxxxxxxx time=\"2020-04-13 10:56:34\" fw=x.x.x.x pri=6 c=1024 gcat=6 m=537 msg=\"Connection Closed\" src=x.x.x.x:51053:X2 srcZone=Encrypted dst=x.x.x.x:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule=\"70 (VPN->LAN)\" vpnpolicy=\"TOI have runt\" app=49178 appName='General HTTPS MGMT' n=408226 fw_action=\"NA\" dpi=0
**Phase 1: Completed pre-decoding.
full event: 'id=firewall sn=xxxxxxxx time=\"2020-04-13 10:56:34\" fw=x.x.x.x pri=6 c=1024 gcat=6 m=537 msg=\"Connection Closed\" src=x.x.x.x:51053:X2 srcZone=Encrypted dst=x.x.x.x:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule=\"70 (VPN->LAN)\" vpnpolicy=\"TOI have runt\" app=49178 appName='General HTTPS MGMT' n=408226 fw_action=\"NA\" dpi=0'
timestamp: '(null)'
hostname: 'centos7-2'
program_name: '(null)'
log: 'id=firewall sn=xxxxxxxx time=\"2020-04-13 10:56:34\" fw=x.x.x.x pri=6 c=1024 gcat=6 m=537 msg=\"Connection Closed\" src=x.x.x.x:51053:X2 srcZone=Encrypted dst=x.x.x.x:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule=\"70 (VPN->LAN)\" vpnpolicy=\"TOI have runt\" app=49178 appName='General HTTPS MGMT' n=408226 fw_action=\"NA\" dpi=0'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
**Phase 3: Completed filtering (rules).
Rule id: '4800'
Level: '0'
Description: 'SonicWall messages grouped.'id=firewall sn=xxxxxxxx time="2020-04-13 10:56:34" fw=x.x.x.x pri=6 c=1024 gcat=6 m=537 msg="Connection Closed" src=x.x.x.x:51053:X2 srcZone=Encrypted dst=x.x.x.x:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0id=firewall sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=6 c=1024 gcat=6 m=537 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"[root@centos]# /var/ossec/bin/ossec-logtest
2020/04/15 13:50:43 ossec-testrule: INFO: Started (pid: 26869).
ossec-testrule: Type one log per line.
id=firewall sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=6 c=1024 gcat=6 m=537 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"
**Phase 1: Completed pre-decoding.
full event: 'id=firewall sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=6 c=1024 gcat=6 m=537 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
timestamp: '(null)'
hostname: 'ip-172-20-1-99'
program_name: '(null)'
log: 'id=firewall sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=6 c=1024 gcat=6 m=537 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
status: '6'
action: 'Connection Closed'
**Phase 3: Completed filtering (rules).
Rule id: '4806'
Level: '0'
Description: 'SonicWall informational message.'<rule id="100050" level="3">
<if_sid>4806</if_sid>
<description>SonicWall informational message.</description>
</rule>
id=firewall sn=00301E0526B1 time="2004-04-01 10:39:35" fw=67.32.44.2 pri=5 c=64 m=36 msg="TCP connection dropped" n=2686 src=67.101.200.27:4507:WAN dst=67.32.44.2:445:LAN rule=0**Phase 1: Completed pre-decoding.
full event: 'id=firewall sn=00301E0526B1 time="2004-04-01 10:39:35" fw=67.32.44.2 pri=5 c=64 m=36 msg="TCP connection dropped" n=2686 src=67.101.200.27:4507:WAN dst=67.32.44.2:445:LAN rule=0'
timestamp: '(null)'
hostname: '6a0538befc4c'
program_name: '(null)'
log: 'id=firewall sn=00301E0526B1 time="2004-04-01 10:39:35" fw=67.32.44.2 pri=5 c=64 m=36 msg="TCP connection dropped" n=2686 src=67.101.200.27:4507:WAN dst=67.32.44.2:445:LAN rule=0'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
status: '5'
action: 'TCP connection dropped'
srcip: '67.101.200.27'
srcport: '4507'
dstip: '67.32.44.2'
dstport: '445'
**Phase 3: Completed filtering (rules).
Rule id: '4805'
Level: '0'
Description: 'SonicWall notice message.'<rule id="100050" level="7">
<if_sid>4100</if_sid>
<description>SonicWall: This is my custom message</description>
</rule><decoder name="sonicwall_custom">
<parent>sonicwall</parent>
<regex>m=(\S+)</regex>
<order>id</order>
</decoder><rule id="100050" level="7">
<if_sid>4100</if_sid>
<description>SonicWall: This is my custom message</description>
</rule>
id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"**Phase 1: Completed pre-decoding.
full event: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
timestamp: '(null)'
hostname: 'centos7-2'
program_name: '(null)'
log: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
id: '30'
status: '1'
**Phase 3: Completed filtering (rules).
Rule id: '100051'
Level: '7'
Description: 'SonicWall: This is my custom message'
**Alert to be generated.Thanks
<decoder name="sonicwall_custom">
<parent>sonicwall</parent>
<regex>m=(\S+)</regex>
<order>id</order>
</decoder>
<decoder name="sonicwall_custom">
<parent>sonicwall</parent>
<regex>pri=(\S+)</regex>
<order>status</order>
</decoder>
id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"
**Phase 1: Completed pre-decoding.
full event: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
timestamp: '(null)'
hostname: 'centos7-2'
program_name: '(null)'
log: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
id: '30'
status: '1'
**Phase 3: Completed filtering (rules).
Rule id: '4100'
Level: '0'
Description: 'Firewall rules grouped.'
<rule id="100051" level="7">
<if_sid>4100</if_sid>
<id>^30$|^32$</id>
<status>^1</status>
<description>SonicWall: This is my custom message</description>
</rule>**Phase 1: Completed pre-decoding.
full event: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
timestamp: '(null)'
hostname: 'centos7-2'
program_name: '(null)'
log: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
id: '30'
status: '1'
**Phase 3: Completed filtering (rules).
Rule id: '100051'
Level: '7'
Description: 'SonicWall: This is my custom message'
**Alert to be generated.
**Phase 1: Completed pre-decoding.
full event: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
timestamp: '(null)'
hostname: 'centos7-2'
program_name: '(null)'
log: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
id: '30'
**Phase 3: Completed filtering (rules).
Rule id: '100051'
Level: '7'
Description: 'SonicWall: This is my custom message'
**Alert to be generated."' Rule id: '100051'
Level: '7'
Description: 'SonicWall: This is my custom message'
**Alert to be generated./var/ossec/bin/update_ruleset
<decoder_exclude>ruleset/decoders/0295-sonicwall_decoders.xml</decoder_exclude><decoder name="sonicwall">
<prematch>id=\.*sn=\.*time=\.*fw\.*pri=\.*c=\.*</prematch>
</decoder>
<decoder name="sonicwall_custom">
<parent>sonicwall</parent>
<regex>m=(\S+)</regex>
<order>id</order>
</decoder>
<decoder name="sonicwall_custom">
<parent>sonicwall</parent>
<regex>pri=(\S+)</regex>
<order>status</order>
</decoder>
id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"**Phase 1: Completed pre-decoding.
full event: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
timestamp: '(null)'
hostname: 'centos7'
program_name: '(null)'
log: 'id=236 sn=12345678 time="2020-04-13 10:56:34" fw=172.16.1.1 pri=1 c=1024 gcat=6 m=30 msg="Connection Closed" src=172.16.1.1:51053:X2 srcZone=Encrypted dst=172.16.1.1:8443:X0 dstZone=Trusted proto=tcp/8443 sent=1644 rcvd=28917 spkt=19 rpkt=28 cdur=1483 rule="70 (VPN->LAN)" vpnpolicy="TOI have runt" app=49178 appName='General HTTPS MGMT' n=408226 fw_action="NA" dpi=0"'
**Phase 2: Completed decoding.
decoder: 'sonicwall'
id: '30'
status: '1'
**Phase 3: Completed filtering (rules).
Rule id: '4811'
Level: '9'
Description: 'SonicWall: Firewall authentication failure.'<decoder name="sonicwall_custom">
<parent>sonicwall</parent>
<regex>LOG_FIELD=(\S+)</regex>
<order>YOUR_FIELD_NAME</order>
</decoder>