hello,
Thank You for info,
So, to summarize
2. Create rule
A Open File 0580-win-security_rules.xml
B. copy intrested rule to some text editor
<rule id="60106" level="3">
<if_sid>60103</if_sid>
<field name="win.system.eventID">^528$|^540$|^673$|^4624$|^4769$</field>
<options>no_full_log</options>
<description>Windows logon success.</description>
<mitre>
<id>T1078</id>
</mitre>
<group>authentication_success,gdpr_IV_32.2,gpg13_7.1,gpg13_7.2,hipaa_164.312.b,nist_800_53_AC.7,nist_800_53_AU.14,pci_dss_10.2.5,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,</group>
</rule>
C. Modyfie rule and copy it to local_rules.xml on the server ???
<rule id="
"100010" level="3" >
<if_sid>60103</if_sid>
<field name="win.system.eventID">^528$|^540$|^673$|^4624$|^4769$</field>
<options>no_full_log</options>
<field name="targetDomainName">MY_DOMAIN_NAME</field>
<match> Administrator </match>
<description>Domian Administrator logon success on the Server.</description>
<mitre>
<id>T1078</id>
</mitre>
<group>authentication_success,gdpr_IV_32.2,gpg13_7.1,gpg13_7.2,hipaa_164.312.b,nist_800_53_AC.7,nist_800_53_AU.14,pci_dss_10.2.5,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,</group>
</rule>
or I can have two field rows instead of match ??
<field name="targetDomainName">MY_DOMAIN_NAME</field>
<field name="targetUserName">Administrator</field>
D. on the Wazuch server in /var/ossec/etc/ossec.conf file put this
<email_alerts>
<rule_id> 100010 </rule_id>
<do_not_delay />
</email_alerts>
restrat Wazuh
Correct :) ??
Thank You