I want to make a filtering rule on the rule 60204 (Multiple Logon Failure Windows) for when it is a list of User and PC to lower the level.
I have a FileServer "FS-001" where the users log in, so for example:
If it is Juan in the Workstation 001 lower the level because it is correct
If it is Marta in the Workstation 002 lower the level because it is correct
But if it is Marta in the Workstation 001 keep the level.
I have the list of users with their allowed workstations.
Also, here is some reference that could be useful:
If you need some help with this, I will need some examples of logs that you have received, including the login information for the different users.
Can you please give me an example rule?
I have tried with CDB List but it didn't work as expected
Each user has only one authorised workstation, if it happens from that user on that workstation it is not an alert but if the user or the workstation is different it is.
Hi, the ruler is not working as expected.
It is still capturing the event of the rule 60204 even if the conditions of the new created rule are fulfilled.
I attach images about the case
Thank you very much, that's what I was expecting ❤️
Sorry for the delay. I want to reproduce your test, but to do so, I need you to share the event exactly as the manager received it.
Could you enable the archive.log (see documentation) by setting <logall> to yes in the ossec.conf file?
Afterward, please find the raw event in /var/ossec/logs/archives/archives.log and share it with me. I need that specific event so I can test it locally.
Hi! You won't be able to test it locally as they are events coming from EventChannel and Wazuh (as far as I understand) doesn't allow testing of these events
Please help me with the rule.