Hi everyone,
Hope you're doing well.
I'm new in the wazuh.
Today i need to send the all logs Eset protect server (syslog) to the wazuh server.
I also installed the agent for this server and create the decoder & rule on wazuh server "
Decoder :
<!-- Modify it at your will. -->
<decoder name="ESET">
<prematch> ESETSRV ERAServer </prematch>
</decoder>
<decoder name="ESET-child">
<parent>ESET</parent>
<regex>\d (\d+-\d+-\.+:\d+:\d+.\.+) ESETSRV (\.+ \.+) - - </regex>
<order>timestamp,hostname</order>
</decoder>
<decoder name="ESET-child">
<parent>ESET</parent>
<regex>{"event_type":"(\w+)","ipv4":"(\.+)","hostname":"(\.+)","source_uuid":"(\.+),"occured":"(\.+)","severity":"(\.+)","domain":"(\.+)","action":"(\.+)","detail":"(\.+).","user":"(\.*)","result":"(\.+)"}</regex>
<order>eset_event_type,eset_ipv4,eset_hostname,eset_source_uuid,eset_occured,eset_severity,eset_domain,eset_action,eset_detail,eset_user,eset_result</order>
</decoder>
<decoder name="ESET-child">
<parent>ESET</parent>
<regex>"occured":"(\.+)","severity":"(\w+)","domain":"(\.+)","action":"(\.+)","detail":"(\.+)","user":"(\.+)","result":"(\.+)"}</regex>
<order>eset_occured,eset_severity,eset_domain,eset_action,eset_detail,eset_user,eset_result</order>
</decoder>
Rule :
<!-- Modify it at your will. -->
<group name="eset,">
<rule id="770000" level="0">
<decoded_as>ESET</decoded_as>
<description>Eset Console Logs</description>
</rule>
<rule id="770001" level="3">
<if_sid>770000</if_sid>
<field name="event_type">^Threat_Event$</field>
<description>Eset: Threat Event rules Group</description>
<group>threat_event,</group>
</rule>
<rule id="770002" level="3">
<if_sid>770000</if_sid>
<field name="event_type">^FirewallAggregated_Event$</field>
<description>Eset: Firewall Aggregated rules Group</description>
<group>firewallaggregated_event,</group>
</rule>
<rule id="770003" level="3">
<if_sid>770000</if_sid>
<field name="event_type">^HipsAggregated_Event$</field>
<description>Eset: HIPS Aggregated rules Group</description>
<group>hipsaggregated_event,</group>
</rule>
<rule id="770004" level="2">
<if_sid>770000</if_sid>
<field name="event_type">^Audit_Event$</field>
<description>Eset: Audit rules Group</description>
<group>audit_event,</group>
</rule>
<rule id="770005" level="3">
<if_sid>770000</if_sid>
<field name="event_type">^EnterpriseInspectorAlert_Event$</field>
<description>Eset: Enterprise Inspector Alert rules Group</description>
<group>enterpriseinspectoralert_event,</group>
</rule>
<rule id="770006" level="3">
<if_sid>770000</if_sid>
<field name="event_type">^EnterpriseInspectorAlert_Event$</field>
<description>Eset: Enterprise Inspector Alert rules Group</description>
<group>enterpriseinspectoralert_event,</group>
</rule>
<rule id="770010" level="5">
<if_sid>770000</if_sid>
<field name="severity">^Warning$</field>
<description>Eset: Warning message was logged from $(hostname)</description>
</rule>
<rule id="770011" level="7">
<if_sid>770000</if_sid>
<field name="severity">^Error$</field>
<description>Eset: Error message was logged from $(hostname)</description>
</rule>
<rule id="770012" level="9">
<if_sid>770000</if_sid>
<field name="severity">^Critical$</field>
<description>Eset: Critical message was logged from $(hostname)</description>
</rule>
</group>
However, my wazuh can not revice and display the logs from eset protect server.
Please advise.
Thanks in advanced.