2017/05/08 02:03:20 ossec-agentd(4102): INFO: Connected to the server (192.168.12.34:1514).2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-AppLocker/EXE and DLL'.2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-AppLocker/MSI and Script'.2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-AppLocker/Packaged app-Deployment'.2017/05/08 02:03:20 ossec-logcollector: ERROR: Could not EvtSubscribe() for (Microsoft-Windows-AppLocker/Packaged app-Deployment) which returned (15007)2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-AppLocker/Packaged app-execution'.2017/05/08 02:03:20 ossec-logcollector: ERROR: Could not EvtSubscribe() for (Microsoft-Windows-AppLocker/Packaged app-execution) which returned (15007)2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Windows PowerShell'.2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-WMI-Activity/Operational'.2017/05/08 02:03:20 ossec-logcollector: ERROR: Could not EvtSubscribe() for (Microsoft-Windows-WMI-Activity/Operational) which returned (15007)2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-Defender/Operational'.2017/05/08 02:03:20 ossec-logcollector: ERROR: Could not EvtSubscribe() for (Microsoft-Windows-Defender/Operational) which returned (15007)2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-WindowsUpdateClient/Operational'.2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-Windows Remote Management/Operational'.2017/05/08 02:03:20 ossec-logcollector: ERROR: Could not EvtSubscribe() for (Microsoft-Windows-Windows Remote Management/Operational) which returned (15007)2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-DriverFrameworks-UserMode/Operational'.2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Setup'.2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-DNS-Client/Operational'.2017/05/08 02:03:20 ossec-logcollector(1951): INFO: Analyzing event log: 'Microsoft-Windows-Windows Firewall With Advanced Security/Firewall'.2017/05/08 02:03:20 ossec-logcollector: INFO: Started (pid: 2612).2017/05/08 02:03:49 ossec-syscheckd: INFO: Syscheck scan frequency: 43200 seconds
2017 May 08 11:03:21 (windows) any->ossec ossec: Agent started: 'windows->any'.
2017 May 08 11:05:28 (windows) any->WinEvtLog 2017 May 08 02:05:27 WinEvtLog: Windows PowerShell: INFORMATION(600): PowerShell: (no user): no domain: WIN-2JIH7DS7L6N: Provider "WSMan" is Started. Details: ProviderName=WSMan NewProviderState=Started SequenceNumber=1 HostName=ConsoleHost HostVersion=2.0 HostId=2d152bf5-fe7d-4b8e-846e-1dbb4300e0df EngineVersion= RunspaceId= PipelineId= CommandName= CommandType= ScriptName= CommandPath= CommandLine=
2017 May 08 11:05:28 (windows) any->WinEvtLog 2017 May 08 02:05:27 WinEvtLog: Windows PowerShell: INFORMATION(600): PowerShell: (no user): no domain: WIN-2JIH7DS7L6N: Provider "Alias" is Started. Details: ProviderName=Alias NewProviderState=Started SequenceNumber=2 HostName=ConsoleHost HostVersion=2.0 HostId=2d152bf5-fe7d-4b8e-846e-1dbb4300e0df EngineVersion= RunspaceId= PipelineId= CommandName= CommandType= ScriptName= CommandPath= CommandLine=
2017 May 08 11:05:28 (windows) any->WinEvtLog 2017 May 08 02:05:27 WinEvtLog: Windows PowerShell: INFORMATION(600): PowerShell: (no user): no domain: WIN-2JIH7DS7L6N: Provider "Environment" is Started. Details: ProviderName=Environment NewProviderState=Started SequenceNumber=3 HostName=ConsoleHost HostVersion=2.0 HostId=2d152bf5-fe7d-4b8e-846e-1dbb4300e0df EngineVersion= RunspaceId= PipelineId= CommandName= CommandType= ScriptName= CommandPath= CommandLine=
2017 May 08 11:05:28 (windows) any->WinEvtLog 2017 May 08 02:05:27 WinEvtLog: Windows PowerShell: INFORMATION(600): PowerShell: (no user): no domain: WIN-2JIH7DS7L6N: Provider "FileSystem" is Started. Details: ProviderName=FileSystem NewProviderState=Started SequenceNumber=4 HostName=ConsoleHost HostVersion=2.0 HostId=2d152bf5-fe7d-4b8e-846e-1dbb4300e0df EngineVersion= RunspaceId= PipelineId= CommandName= CommandType= ScriptName= CommandPath= CommandLine=
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/a24e9f70-0317-4ba3-98c0-48c90a9a47fe%40googlegroups.com.