This is my first post so plese be gentle ;)
im trying to send audit logs from mssql to wazuh to get alerts when someone is executing query
problem is that there is no rules for that matches on message comes from mssql
what i see is that eventID is 33205 and message comes with severity value "severityValue\":\"AUDIT_SUCCESS\" i check that there is a such rule but nothing match
i try to create rule but looks like is not working
<rule id="100103" level="0">
<if_sid>60001</if_sid>
<field name="win.system.severityValue">^AUDIT_SUCCESS$</field>
<description>Windows audit success event</description>
</rule>
Here is example of message
{"timestamp":"2019-09-13T09:41:29.47+0300","agent":{"id":"041","name":"DB01","ip":"10.22.3.61"},"manager":{"name":"IS3.domain.office"},"id":"1568356889.700828450","full_log":"{\"win\":{\"system\":{\"providerName\":\"MSSQL$DB01\",\"eventID\":\"33205\",\"level\":\"0\",\"task\":\"5\",\"keywords\":\"0xa0000000000000\",\"systemTime\":\"2019-09-13T06:41:24.593240800Z\",\"eventRecordID\":\"3009319\",\"channel\":\"Application\",\"computer\":\"DB01.domain.prod\",\"severityValue\":\"AUDIT_SUCCESS\",\"message\":\"Audit event: audit_schema_version:1 event_time:2019-09-13 06:41:23.7965120 sequence_number:1 action_id:SL succeeded:true is_column_permission:true session_id:89 server_principal_id:288 database_principal_id:77 target_server_principal_id:0 target_database_principal_id:0 object_id:2046630334 user_defined_event_id:0 class_type:U permission_bitmask:00000000000000000000000000000001 sequence_group_id:4E88E82C-C3FF-4A6F-9CD0-D92D9FD16359 session_server_principal_name:OFFICE\\\\sys.test server_principal_name:OFFICE\\\\sys.test server_principal_sid:010500000000000515000000f4c6826aa3951380da98d5dd0b120000 database_principal_name:OFFICE\\\\sys.test target_server_principal_name: target_server_principal_sid: target_database_principal_name: server_instance_name:DB01\\\\DB01 database_name:test schema_name:dbo object_name:message statement:SELECT id, medium, gate_message_id, charge_operation_id, datediff(hour, dt, getdate()) hours_old FROM message WHERE status=5 and dt>dateadd(hour, -30, getdate()) and medium = 'P' ORDER BY id additional_information: user_defined_information: .\"},\"eventdata\":{\"data\":\"audit_schema_version:1 event_time:2019-09-13 06:41:23.7965120 sequence_number:1 action_id:SL succeeded:true is_column_permission:true session_id:89 server_principal_id:288 database_principal_id:77 target_server_principal_id:0 target_database_principal_id:0 object_id:2046630334 user_defined_event_id:0 class_type:U permission_bitmask:00000000000000000000000000000001 sequence_group_id:4E88E82C-C3FF-4A6F-9CD0-D92D9FD16359 session_server_principal_name:OFFICE\\\\sys.test server_principal_name:OFFICE\\\\sys.test server_principal_sid:010500000000000515000000f4c6826aa3951380da98d5dd0b120000 database_principal_name:OFFICE\\\\sys.test target_server_principal_name: target_server_principal_sid: target_database_principal_name: server_instance_name:DB01\\\\DB01 database_name:test schema_name:dbo object_name:message statement:SELECT id, medium, gate_message_id, charge_operation_id, datediff(hour, dt, getdate()) hours_old FROM message WHERE status=5 and dt>dateadd(hour, -30, getdate()) and medium = 'P' ORDER BY id additional_information: user_defined_information:\"}}}","decoder":{"name":"windows_eventchannel"},"data":{"win":{"system":{"providerName":"MSSQL$DB01","eventID":"33205","level":"0","task":"5","keywords":"0xa0000000000000","systemTime":"2019-09-13T06:41:24.593240800Z","eventRecordID":"3009319","channel":"Application","computer":"DB.domain.prod","severityValue":"AUDIT_SUCCESS","message":"Audit event: audit_schema_version:1 event_time:2019-09-13 06:41:23.7965120 sequence_number:1 action_id:SL succeeded:true is_column_permission:true session_id:89 server_principal_id:288 database_principal_id:77 target_server_principal_id:0 target_database_principal_id:0 object_id:2046630334 user_defined_event_id:0 class_type:U permission_bitmask:00000000000000000000000000000001 sequence_group_id:4E88E82C-C3FF-4A6F-9CD0-D92D9FD16359 session_server_principal_name:OFFICE\\sys.test server_principal_name:OFFICE\\sys.test server_principal_sid:010500000000000515000000f4c6826aa3951380da98d5dd0b120000 database_principal_name:OFFICE\\sys.test target_server_principal_name: target_server_principal_sid: target_database_principal_name: server_instance_name:DB-SICP00001\\DBSICP01 database_name:test schema_name:dbo object_name:message statement:SELECT id, medium, gate_message_id, charge_operation_id, datediff(hour, dt, getdate()) hours_old FROM message WHERE status=5 and dt>dateadd(hour, -30, getdate()) and medium = 'P' ORDER BY id additional_information: user_defined_information: ."},"eventdata":{"data":"audit_schema_version:1 event_time:2019-09-13 06:41:23.7965120 sequence_number:1 action_id:SL succeeded:true is_column_permission:true session_id:89 server_principal_id:288 database_principal_id:77 target_server_principal_id:0 target_database_principal_id:0 object_id:2046630334 user_defined_event_id:0 class_type:U permission_bitmask:00000000000000000000000000000001 sequence_group_id:4E88E82C-C3FF-4A6F-9CD0-D92D9FD16359 session_server_principal_name:OFFICE\\sys.test server_principal_name:OFFICE\\sys.test server_principal_sid:010500000000000515000000f4c6826aa3951380da98d5dd0b120000 database_principal_name:OFFICE\\sys.test target_server_principal_name: target_server_principal_sid: target_database_principal_name: server_instance_name:DB-SICP00001\\DBSICP01 database_name:test schema_name:dbo object_name:message statement:SELECT id, medium, gate_message_id, charge_operation_id, datediff(hour, dt, getdate()) hours_old FROM message WHERE status=5 and dt>dateadd(hour, -30, getdate()) and medium = 'P' ORDER BY id additional_information: user_defined_information:"}}},"location":"EventChannel"}