Hi Chrisitian,
There's no problem, I know that you were taking care of other cases.
As you requested, this is the rule id 1000002:
<rule id="100002" level="9">
<if_group>authentication_failed</if_group>
<time>06:00 pm-8:30 am</time>
<description>Failed login during non-business hours</description>
<group>login_time,authentication_failed,</group>
<options>alert_by_email</options>
</rule>
I again have tested the trigger of the rule and this is the alert message recorded in alerts.json file:
{"timestamp":"2022-03-28T23:55:40.490+0100","rule":{"level":9,"description":"Failed login during non-business hours","id":"100002","firedtimes":2,"mail":true,"groups":["policy_violation","local","login_time","authentication_failed"]},"agent":{"id":"001","name":"centos-agent","ip":"x.x.x.x"},"manager":{"name":"wazuh"},"id":"1648508140.81484893","full_log":"Mar 28 04:14:29 hostname sshd[31646]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=y.y.y.y","predecoder":{"program_name":"sshd","timestamp":"Mar 28 04:14:29","hostname":"hostname"},"decoder":{"name":"pam"},"data":{"srcip":"y.y.y.y","uid":"0","euid":"0","tty":"ssh"},"location":"/var/log/secure"
{"timestamp":"2022-03-28T23:55:44.454+0100","rule":{"level":9,"description":"Failed login during non-business hours","id":"100002","firedtimes":3,"mail":true,"groups":["policy_violation","local","login_time","authentication_failed"]},"agent":{"id":"001","name":"centos-agent","ip":"x.x.x.x"},"manager":{"name":"wazuh"},"id":"1648508144.81532656","full_log":"Mar 28 04:14:31 hostname sshd[31646]: Failed password for invalid user dfdfdfdf from y.y.y.y port x ssh2","predecoder":{"program_name":"sshd","timestamp":"Mar 28 04:14:31","hostname":"hostname"},"decoder":{"parent":"sshd","name":"sshd"},"data":{"srcip":"y.y.y.y","srcuser":"dfdfdfdf"},"location":"/var/log/secure"}
Finally, the report is empty as usual:
2022/03/29 00:00:10 wazuh-monitord: INFO: Starting new log after rotation.
2022/03/29 00:00:10 wazuh-monitord: INFO: Starting daily reporting for 'Daily report'
2022/03/29 00:00:10 wazuh-monitord: ERROR: date or location not NULL or p is NULL
2022/03/29 00:00:15 wazuh-monitord: INFO: Report 'Daily report' completed and zero alerts post-filter.
2022/03/29 00:00:15 wazuh-monitord: INFO: Report 'Daily report' empty.
Regards.