I know is oldie but...
1)Insert USB
2)I get in the Agent Event Viewer the Event 6416
El sistema ha reconocido un nuevo dispositivo externo.
Asunto:
Id. de seguridad: SYSTEM
Nombre de cuenta: NB16032201$
Dominio de la cuenta: BEPSA
Id. de inicio de sesión: 0x3E7
Id. de dispositivo: HID\VID_1B1C&PID_1B3C&MI_00&Col01\7&1c409cb&0&0000
Nombre del dispositivo: HID-compliant mouse
Id. de clase: {4d36e96f-e325-11ce-bfc1-08002be10318}
Nombre de clase: Mouse
Id. de proveedor:
HID\VID_1B1C&PID_1B3C&REV_0308&MI_00&Col01
HID\VID_1B1C&PID_1B3C&MI_00&Col01
HID\VID_1B1C&UP:0001_U:0002
HID_DEVICE_SYSTEM_MOUSE
HID_DEVICE_UP:0001_U:0002
HID_DEVICE
Id. compatible:
.
.
.
3 )
"agent":{"id":"001","name":"nb16032201","ip":"192.168.100.4"},"manager":{"name":"tmpltubuntu"},"id":"1663655745.52100","full_log":"{\"win\":{\"system\":{\"providerName\":\"hcmon\",\"eventID\":\"0\",\"version\":\"0\",\"level\":\"3\",\"task\":\"0\",\"opcode\":\"0\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2022-09-20T06:35:44.4868375Z\",\"eventRecordID\":\"111412\",\"processID\":\"4\",\"threadID\":\"11960\",\"channel\":\"System\",\"computer\":\"
nb16032201.bepsa.com.py\",\"severityValue\":\"WARNING\",\"message\":\"\\\"Detected unrecognized USB driver (\\\\Driver\\\\USBPcap).\\\"\"},\"eventdata\":{\"binary\":\"00000000020028000000000000000080000000000000000000000000000000000000000000000000\",\"data\":\"\\\\\\\\Device\\\\\\\\hcmon, \\\\\\\\Driver\\\\\\\\USBPcap\"}}}","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"hcmon","eventID":"0","version":"0","level":"3","task":"0","opcode":"0","keywords":"0x80000000000000","systemTime":"2022-09-20T06:35:44.4868375Z","eventRecordID":"111412","processID":"4","threadID":"11960","channel":"System","computer":"
nb16032201.bepsa.com.py","severityValue":"WARNING","message":"\"Detected unrecognized USB driver (\\Driver\\USBPcap).\""},"eventdata":{"binary":"00000000020028000000000000000080000000000000000000000000000000000000000000000000","data":"\\\\Device\\\\hcmon, \\\\Driver\\\\USBPcap"}}},"location":"EventChannel"}
{"timestamp":"2022-09-20T02:35:45.556-0400","agent":{"id":"001","name":"nb16032201","ip":"192.168.100.4"},"manager":{"name":"tmpltubuntu"},"id":"1663655745.52100","full_log":"{\"win\":{\"system\":{\"providerName\":\"hcmon\",\"eventID\":\"0\",\"version\":\"0\",\"level\":\"3\",\"task\":\"0\",\"opcode\":\"0\",\"keywords\":\"0x80000000000000\",\"systemTime\":\"2022-09-20T06:35:44.4868375Z\",\"eventRecordID\":\"111413\",\"processID\":\"4\",\"threadID\":\"11960\",\"channel\":\"System\",\"computer\":\"
nb16032201.bepsa.com.py\",\"severityValue\":\"WARNING\",\"message\":\"\\\"Detected unrecognized USB driver (\\\\Driver\\\\USBPcap).\\\"\"},\"eventdata\":{\"binary\":\"00000000020028000000000000000080000000000000000000000000000000000000000000000000\",\"data\":\"\\\\\\\\Device\\\\\\\\hcmon, \\\\\\\\Driver\\\\\\\\USBPcap\"}}}","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"hcmon","eventID":"0","version":"0","level":"3","task":"0","opcode":"0","keywords":"0x80000000000000","systemTime":"2022-09-20T06:35:44.4868375Z","eventRecordID":"111413","processID":"4","threadID":"11960","channel":"System","computer":"
nb16032201.bepsa.com.py","severityValue":"WARNING","message":"\"Detected unrecognized USB driver (\\Driver\\USBPcap).\""},"eventdata":{"binary":"00000000020028000000000000000080000000000000000000000000000000000000000000000000","data":"\\\\Device\\\\hcmon, \\\\Driver\\\\USBPcap"}}},"location":"EventChannel"}
4) I've got no alert in /var/ossec/logs/alerts/alerts.json