USB monitoring, regex not working.

Skip to first unread message

andrzej oto

Dec 1, 2022, 4:11:32 AM12/1/22
to Wazuh mailing list
I want to monitor USB devices
I use these decoders

<decoder name="windows_fields">
  <order>usb.vendor, usb.product, usb.rev, usb.serial_number</order>

I can see the event, but the regex doesn't work
I have read these articles

I created a rule

<rule id="100002" level="5">
  <field name="win.system.eventID">^6416$</field>
  <description>Windows: Authorized PNP device connected.</description>

<rule id="100003" level="7">
  <list field="win.eventdata.deviceId" lookup="not_match_key">etc/lists/usb-devices</list>
  <description>Windows: Unauthorized PNP device connected.</description>

but i need to modify my list of usb devices
and add everything


I think it's because of the regex problem, do you have an idea what could be causing this?

Chantal Belen Kelm

Dec 1, 2022, 5:32:44 AM12/1/22
to Wazuh mailing list
Hello, how are you? I will review the information you sent and make some checks.

Chantal Belen Kelm

Dec 2, 2022, 11:21:42 AM12/2/22
to Wazuh mailing list
can you share with me the log that arrives to the wazuh manager?

andrzej oto

Dec 20, 2022, 7:10:10 AM12/20/22
to Chantal Belen Kelm, Wazuh mailing list
Yes please,

You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit
To unsubscribe from this group and all its topics, send an email to
To view this discussion on the web visit
Reply all
Reply to author
0 new messages