Hi Sandra,
Since you know the complete history of our use case, so that’s why addressed the new case to you of the same old Pulse secure logs on Wazuh manager.
Opened a new case, may we have a custom rule and decoder for authentication failed for the below Pulse secure log on Wazuh manager, since this is coming three times from same source IP with different context, can we club them into 1 common rule and decoder, such that if any of the three logs come on Wazuh Manager, we get the GEO information associated with source IP.
1 2021-06-15T05:43:10+02:00 seliinfw00006.hubseka.ericsson.se PulseSecure: - - - 2021-06-15 05:43:10 - seliinfw00006 - [203.13.128.104] kalle....@optus.com.au(CUST)[] - Authentication failure for AD server 'vmxe014-vmxe064': specified account does not exist
1 2021-06-15T05:43:10+02:00 seliinfw00006.hubseka.ericsson.se PulseSecure: - - - 2021-06-15 05:43:10 - seliinfw00006 - [203.13.128.104] optus.com.au\kalle.iivonen(CUST)[] - Primary authentication failed for optus.com.au\kalle.iivonen/vmxe014-vmxe064 from 203.13.128.104
1 2021-06-15T05:43:10+02:00 seliinfw00006.hubseka.ericsson.se PulseSecure: - - - 2021-06-15 05:43:10 - seliinfw00006 - [203.13.128.104] optus.com.au\kalle.iivonen(CUST)[] - Login failed using auth server vmxe014-vmxe064 (Active Directory).
Reason: Invalid Credentials
For the above authentication failed log , may we have a red colour points on Kibana map, and can we simultaneously have on the same map view both green and red points?( User login successful and user login failed)
Also , I have one doubt ,
The geo information would be coming for only those alerts of Pulse secure associated with source ip on Wazuh manager , whose custom rule and decoder is set? I mean the geo location wont come every alert of Pulse secure associated with source IP on Wazuh manager..Am I right in my understanding?
Waiting to hear from you.
BR
//Prachi
Hi Sandra,
Sincere Apologies for the delay in reply, everything is working perfectly fine as per your guidance and we can happily close the case.
Thanks for your patience all throughout and time.
BR
//Prachi
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
wazuh+un...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/wazuh/CA%2BFx3jx8v7%2BipURHdERM8eMAe1km2dS7uSeGN8%2Bq_nw8Pgyxdg%40mail.gmail.com.