Hi every one,
I'm tring to configure usb check in order to match usb devices with a predefined list as described in the blog:
https://blog.wazuh.com/monitoring-usb-drives-in-windows-using-wazuh/I followed the guide step by steb and when I execute the configuration controll all seems works fine, but I have the following error on the web interface as follow:
"Manager - Status: Wazuh API returned an error message. Error: Error reading decoder files: 0380-windows_decoders.xml. Error: not well-formed (invalid token): line 680, column 26"xml decoder code in error is:
<decoder name="windows_fields">
<type>windows</type>
<parent>windows</parent>
<regex>USBSTOR#Disk&Ven_(\S*)&Prod_(\S*)&Rev_(\.*)#(\S*)&0#\S*\s</regex>
<order>usb.vendor, usb.product, usb.rev, usb.serial_number</order>
</decoder>
I'm do not know where is the problem, someone can help me?
I'm do not know where is the problem, someone can help me?
thanks in advance
Marco