Custom Rules

59 views
Skip to first unread message

clsamc...@gmail.com

unread,
May 12, 2022, 1:06:34 PM5/12/22
to Wazuh mailing list
Does anyone see what's wrong with this rule:

<group name="http_errors">
  <rule id="100003" level="0">
    <if_sid>31151,31101,31533</if_sid>
    <list field="srcip" lookup="address_match_key">lists/white_list</list>
    <description>Quiet: Whitelisted IPs</description>
   </rule>
</group>

I'm trying to suppress alerts from white listed IPs. My white_list file is in the following format:

IP:ID

So, for example, 192.168.168.168:User1

I continue to receive alerts for the whitelisted IPs.

I am using Wazuh v4.3.0

Thanks.

clsamc...@gmail.com

unread,
May 12, 2022, 2:43:07 PM5/12/22
to Wazuh mailing list
Apparently the problem is that analysisd is not processing the file, but I don't know why. Permissions and ownership match others in the etc/lists directory.

clsamc...@gmail.com

unread,
May 12, 2022, 4:05:04 PM5/12/22
to Wazuh mailing list
Okay, got it.

First, add your list to ossec.conf. Second, the rules entry should point to white-list.cdb. Works.

Emiliano Zorn

unread,
May 12, 2022, 5:23:21 PM5/12/22
to Wazuh mailing list
Hello team!

Can you please corroborate that the CDB list you are looking for is in the correct path?

You're redirecting to lists/white_lists, where by default are in etc/lists/

Let me know if that work for you.

Regards.

Emiliano Zorn

unread,
May 12, 2022, 5:25:22 PM5/12/22
to Wazuh mailing list
Hello there! I just saw your last message.

I'm glad it worked for you! Just out of curiosity, did you had to modify something in the rule or just in the ossec.conf?

clsamc...@gmail.com

unread,
May 17, 2022, 12:16:55 PM5/17/22
to Wazuh mailing list
Hi

Thank you for the reply. I think the path issue was likely a result of the many edits. The solution was adding to the lists section of ossec.conf.

Thanks, again.

Emiliano Zorn

unread,
May 19, 2022, 2:05:22 PM5/19/22
to Wazuh mailing list
Hello there!

Thanks for the explanation.

Do not hesitate to write again in case of need.

Regards.
Reply all
Reply to author
Forward
0 new messages