very good.
I have another question.
_index
wazuh-alerts-4.x-2024.04.20
agent.id 000
agent.name wazuh
data.command
add
data.dstuser
attaquant
data.origin.module
wazuh-execd
data.origin.name node01
data.parameters.alert.agent.id 000
data.parameters.alert.agent.name wazuh
data.parameters.alert.data.dstuser
attaquant
data.parameters.alert.data.fw
Fw_Compans1
data.parameters.alert.data.logtype
xvpn
data.parameters.alert.data.msg
Error during authentication : user not found in ldap
data.parameters.alert.data.startime
2024-04-20 09:56:59
data.parameters.alert.data.time
2024-04-20 09:56:59
data.parameters.alert.data.tz +0200
data.parameters.alert.decoder.name stormshield_decoder
data.parameters.alert.full_log
1
2024-04-20T09:56:59+02:00 Fw1 openvpn_auth - - - id=firewall
time="2024-04-20 09:56:59" fw="Fw1" tz=+0200 startime="2024-04-20
09:56:59" ipproto="UDP" user="attaquant" domain="
masociete.fr" src=88.166.26.80 msg="Error during authentication : user not found in ldap" logtype="xvpn"
data.parameters.alert.id 1713599817.44042456
data.parameters.alert.location
192.168.1.1
data.parameters.alert.manager.name wazuh
data.parameters.alert.rule.description
Acces invalide en VPN
data.parameters.alert.rule.firedtimes
67
data.parameters.alert.rule.groups
firewall
data.parameters.alert.rule.id 100014
data.parameters.alert.rule.level
12
data.parameters.alert.rule.mail
true
data.parameters.alert.timestamp
2024-04-20T07:56:57.908+0000
data.parameters.extra_args
data.parameters.program
active-response/bin/firewall-drop
data.version
1
decoder.name ar_log_json
decoder.parent
ar_log_json
full_log
2024/04/20
07:56:57 active-response/bin/firewall-drop:
{"version":1,"origin":{"name":"node01","module":"wazuh-execd"},"command":"add","parameters":{"extra_args":[],"alert":{"timestamp":"2024-04-20T07:56:57.908+0000","rule":{"level":12,"description":"Acces
invalide en
VPN","id":"100014","firedtimes":67,"mail":true,"groups":["firewall"]},"agent":{"id":"000","name":"wazuh"},"manager":{"name":"wazuh"},"id":"1713599817.44042456","full_log":"1
2024-04-20T09:56:59+02:00 Fw1 openvpn_auth - - - id=firewall
time=\"2024-04-20 09:56:59\" fw=\"Fw1\" tz=+0200 startime=\"2024-04-20
09:56:59\" ipproto=\"UDP\" user=\"attaquant\" domain=\"
masociete.fr\"
src=88.166.26.80 msg=\"Error during authentication : user not found in
ldap\"
logtype=\"xvpn\"","decoder":{"name":"stormshield_decoder"},"data":{"dstuser":"attaquant","time":"2024-04-20
09:56:59","fw":"Fw1","tz":"+0200","startime":"2024-04-20
09:56:59","msg":"Error during authentication : user not found in
ldap","logtype":"xvpn"},"location":"192.168.1.1"},"program":"active-response/bin/firewall-drop"}}
id
1713599819.44053511
input.type
log
location
/var/ossec/logs/active-responses.log
manager.name wazuh
rule.description
Alerte : IP BLOQUEE
rule.firedtimes
67
rule.groups
local, syslog, sshd, web
rule.id 100003
rule.level
13
rule.mail
true
timestamp
Apr 20, 2024 @ 09:56:59.649