Thanks. Wazuh not running after
systemctl restart wazuh-manager
I adjust /var/ossec/ruleset/rules/0095-sshd_rules.xml
<rule id="5748" level="6">
<if_sid>5700</if_sid>
<same_user />
<same_srcip />
<description> sshd: corrupted MAC on input: IP:$(srcip)
failed to connect with user: $(dstuser).</description>
<group>pci_dss_10.6.1,gpg13_4.3,gdpr_IV_35.7.d,hipaa_164.312.b,nist_800_53_AU.6,tsc_CC7.2,tsc_CC7.3,</group>
</rule>
Return error:
Jul 25 08:52:46 siem env[10190]: 2023/07/25 08:52:46
wazuh-analysisd: ERROR: Invalid use of frequency/context options.
Missing if_matched on rule '5748'.
Jul 25 08:52:46 siem env[10190]: 2023/07/25 08:52:46
wazuh-analysisd: CRITICAL: (1220): Error loading the rules:
'ruleset/rules/0095-sshd_rules.xml'.
Jul 25 08:52:46 siem env[10163]: wazuh-analysisd: Configuration
error. Exiting
Jul 25 08:52:46 siem systemd[1]: wazuh-manager.service: Control
process exited, code=exited, status=1/FAILURE
Jul 25 08:52:46 siem systemd[1]: wazuh-manager.service: Failed
with result 'exit-code'.
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/394ea1a2-3336-428b-a925-1a9092a6b898n%40googlegroups.com.
Hi, don't worry about the delay.
Event does not match, example:
In the client:
/var/log/auth.log
Jul 31 06:42:47 fw sshd[24423]: Unable to negotiate with
218.92.0.4 port 15586: no matching MAC found. Their offer:
hmac-md5,hmac-md5-96,hmac-sha1,hmac-sha1-96,hmac-ripemd160,hmac-ri...@openssh.com
[preauth]
Jul 31 10:12:44 fw sshd[28412]: Unable to negotiate with
218.92.0.4 port 18938: no matching MAC found. Their offer:
hmac-md5,hmac-md5-96,hmac-sha1,hmac-sha1-96,hmac-ripemd160,hmac-ri...@openssh.com
[preauth]
In siem dashboard does not generate alert ou block.
Follows rule:
| Assunto: | Re: ssh event dont block |
|---|---|
| Data: | Mon, 31 Jul 2023 05:22:38 -0700 (PDT) |
| De: | 'John Ebuka Onyejegbu' via Wazuh mailing list <wa...@googlegroups.com> |
| Responder a: | John Ebuka Onyejegbu <john.on...@wazuh.com> |
| Para: | Wazuh mailing list <wa...@googlegroups.com> |