<rule id="18118" level="9"> <if_sid>18104</if_sid> <id>^517$|^1102$</id> <description>Windows audit log was cleared.</description> <group>logs_cleared,pci_dss_10.6.1,</group> </rule>
{"timestamp":"2017-03-12T22:35:17+0000","rule":{},"agent":{"id":"011","name":"Agent11","ip":"10.0.0.11"},"manager":{"name":"SysLog01.x.y.z"},"dstuser":"(no user)","full_log":"2017 Mar 12 22:35:17 WinEvtLog: Security: INFORMATION(1102): Microsoft-Windows-Eventlog: (no user): no domain: Agent11.x.y.z: The audit log was cleared. Subject: Security ID: S-1-5-21-123456789-123456789-123456789-1155 Account Name: TestUser Domain Name: TestDomain Logon ID: 0x3CEF5C2","program_name":"WinEvtLog","id":"1102","status":"INFORMATION","data":"Microsoft-Windows-Eventlog","system_name":"Agent11.x.y.z","account_name":"TestUser","logon_id":"","decoder":{"parent":"windows","name":"windows"},"location":"WinEvtLog"}
2017 Mar 12 22:35:17 WinEvtLog: Security: INFORMATION(1102): Microsoft-Windows-Eventlog: (no user): no domain: Agent11.x.y.z: The audit log was cleared. Subject: Security ID: S-1-5-21-123456789-123456789-123456789-1155 Account Name: TestUser Domain Name: TestDomain Logon ID: 0x3CEF5C2
**Phase 1: Completed pre-decoding.
full event: '2017 Mar 12 22:35:17 WinEvtLog: Security: INFORMATION(1102): Microsoft-Windows-Eventlog: (no user): no domain: Agent11.x.y.z: The audit log was cleared. Subject: Security ID: S-1-5-21-123456789-123456789-123456789-1155 Account Name: TestUser Domain Name: TestDomain Logon ID: 0x3CEF5C2'
hostname: 'ubuntu5'
program_name: 'WinEvtLog'
log: 'Security: INFORMATION(1102): Microsoft-Windows-Eventlog: (no user): no domain: Agent11.x.y.z: The audit log was cleared. Subject: Security ID: S-1-5-21-123456789-123456789-123456789-1155 Account Name: TestUser Domain Name: TestDomain Logon ID: 0x3CEF5C2'
**Phase 2: Completed decoding.
decoder: 'windows'
status: 'INFORMATION'
id: '1102'
extra_data: 'Microsoft-Windows-Eventlog'
dstuser: '(no user)'
system_name: 'Agent11.x.y.z'
account_name: 'TestUser'
logon_id: ''
**Phase 3: Completed filtering (rules).
Rule id: '18101'
Level: '0'
Description: 'Windows informational event.'
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/2ec0d01d-5522-4b53-9e25-e99a0870535d%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.