--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/45555a54-0854-4593-a090-29e7cc19066f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
root@host:~# ossec-logtest
type=SYSCALL msg=audit(1488716672.216:80669): arch=c000003e syscall=263 success=no exit=-13 a0=ffffffffffffff9c a1=7560c0 a2=0 a3=7ffe2eb6ee90 items=2 ppid=57426 pid=57453 auid=0 uid=1007 gid=1007 euid=1007 suid=1007 fsuid=1007 egid=1007 sgid=1007 fsgid=1007 tty=pts0 ses=10376 comm="rm" exe="/usr/bin/rm" key="delete" type=CWD msg=audit(1488716672.216:80669): cwd="/var/ossec/bin" type=PATH msg=audit(1488716672.216:80669): item=0 name="/etc/" inode=134320321 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00 objtype=PARENT type=PATH msg=audit(1488716672.216:80669): item=1 name="/etc/ossec-init.conf" inode=165346229 dev=fd:00 mode=0100640 ouid=0 ogid=993 rdev=00:00 objtype=DELETE
**Phase 1: Completed pre-decoding.
full event: 'type=SYSCALL msg=audit(1488716672.216:80669): arch=c000003e syscall=263 success=no exit=-13 a0=ffffffffffffff9c a1=7560c0 a2=0 a3=7ffe2eb6ee90 items=2 ppid=57426 pid=57453 auid=0 uid=1007 gid=1007 euid=1007 suid=1007 fsuid=1007 egid=1007 sgid=1007 fsgid=1007 tty=pts0 ses=10376 comm="rm" exe="/usr/bin/rm" key="delete" type=CWD msg=audit(1488716672.216:80669): cwd="/var/ossec/bin" type=PATH msg=audit(1488716672.216:80669): item=0 name="/etc/" inode=134320321 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00 objtype=PARENT type=PATH msg=audit(1488716672.216:80669): item=1 name="/etc/ossec-init.conf" inode=165346229 dev=fd:00 mode=0100640 ouid=0 ogid=993 rdev=00:00 objtype=DELETE'
hostname: 'ubuntu'
program_name: '(null)'
log: 'type=SYSCALL msg=audit(1488716672.216:80669): arch=c000003e syscall=263 success=no exit=-13 a0=ffffffffffffff9c a1=7560c0 a2=0 a3=7ffe2eb6ee90 items=2 ppid=57426 pid=57453 auid=0 uid=1007 gid=1007 euid=1007 suid=1007 fsuid=1007 egid=1007 sgid=1007 fsgid=1007 tty=pts0 ses=10376 comm="rm" exe="/usr/bin/rm" key="delete" type=CWD msg=audit(1488716672.216:80669): cwd="/var/ossec/bin" type=PATH msg=audit(1488716672.216:80669): item=0 name="/etc/" inode=134320321 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00 objtype=PARENT type=PATH msg=audit(1488716672.216:80669): item=1 name="/etc/ossec-init.conf" inode=165346229 dev=fd:00 mode=0100640 ouid=0 ogid=993 rdev=00:00 objtype=DELETE'
**Phase 2: Completed decoding.
decoder: 'auditd'
audit.type: 'SYSCALL'
audit.id: '80669'
audit.syscall: '263'
audit.success: 'no'
audit.exit: '-13'
audit.ppid: '57426'
audit.pid: '57453'
audit.auid: '0'
audit.uid: '1007'
audit.gid: '1007'
audit.euid: '1007'
audit.suid: '1007'
audit.fsuid: '1007'
audit.egid: '1007'
audit.sgid: '1007'
audit.fsgid: '1007'
audit.tty: 'pts0'
audit.session: '10376'
audit.command: 'rm'
audit.exe: '/usr/bin/rm'
audit.key: 'delete'
audit.cwd: '/var/ossec/bin'
audit.directory.name: '/etc/'
audit.directory.inode: '134320321'
audit.directory.mode: '040755'
audit.file.name: '/etc/ossec-init.conf'
audit.file.inode: '165346229'
audit.file.mode: '0100640'
**Phase 3: Completed filtering (rules).
Rule id: '80700'
Level: '0'
Description: 'Audit: messages grouped.'
As you can see, the matched rule has level 0, so it is not being put into the alert log. So you should write a rule for this event. If you have any problem with this write back to us.
Kind regards.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/0d393dc4-c946-4d18-a2a4-0ee0d3948419%40googlegroups.com.
<rule id="80700" level="0"> -> <rule id="80700" level="3">
<rule id="80700" level="3" overwrite="yes">
<decoded_as>auditd</decoded_as>
<description>Audit: messages grouped.</description>
</rule>
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/8931de08-f133-4bfb-9b7f-dabe5f8a4f2e%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/e8840f23-f826-4c9c-b899-873914c96e96%40googlegroups.com.