2023-05-10T09:52:13+02:00 pfsense php-fpm[68044]: /snort/snort_blocked.php: Successful login for user 'admin' from: 192.168.240.3 (Local Database)
[root@curiosity decoders]# /var/ossec/bin/wazuh-logtest-legacy
2023/05/10 15:30:44 wazuh-testrule: WARNING: (7613): Rule ID '31101' does not exist but 'overwrite' is set to 'yes'. Still, the rule will be loaded.
2023/05/10 15:30:44 wazuh-testrule: INFO: Started (pid: 2715).
Since Wazuh v4.1.0 this binary is deprecated. Use wazuh-logtest instead
wazuh-testrule: Type one log per line.
2023-05-10T09:52:13+02:00 pfsense php-fpm[68044]: /snort/snort_blocked.php: Successful login for user 'admin' from: 192.168.240.3 (Local Database)
**Phase 1: Completed pre-decoding.
full event: '2023-05-10T09:52:13+02:00 pfsense php-fpm[68044]: /snort/snort_blocked.php: Successful login for user 'admin' from: 192.168.240.3 (Local Database)'
timestamp: '2023-05-10T09:52:13+02:00'
hostname: 'pfsense'
program_name: 'php-fpm'
log: '/snort/snort_blocked.php: Successful login for user 'admin' from: 192.168.240.3 (Local Database)'
**Phase 2: Completed decoding.
No decoder matched.
<decoder name="local_decoder_example">
<program_name>local_decoder_example</program_name>
</decoder>
<decoder name="pfsense-custom">
<prematch>php-fpm</prematch>
</decoder>
<decoder name="pfsense-custom">
<parent>pfsense-custom</parent>
<regex>\.+: \w+ \w+ \w+ \w+ (\w+) \w+: (\d+.\d+.\d+.\d+) \.+</regex>
<order>user, srcip</order>
</decoder>
<group name="pfsense-custom">
<rule id="100002" level="5">
<decoded_as>pfsense-custom</decoded_as>
<description>PFsense alert: $(description)</description>
</rule>
</group>
--
You received this message because you are subscribed to a topic in the Google Groups "Wazuh mailing list" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/wazuh/q6QXEFgJ8aM/unsubscribe.
To unsubscribe from this group and all its topics, send an email to wazuh+un...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/3cc73a9b-6e6a-413c-8992-abf995d5df66n%40googlegroups.com.