Re: Issue with scripts/services/evt[application|security|system]
Orion Poplawski <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
On 06/28/2011 02:56 PM, William Voyek wrote: > Hello All, > > I'm having an issue with the Windows Event Log parsing scripts. I have > a syslog server with a fresh install of CentOS 5.6 with the latest > version of Logwatch (7.4.0). > > I have attached the logfile to this email. > > Can someone can help me correct this either on the SNARE end or the > logwatch end? Wow, interesting to hear of someone else actually trying to use this code. Anyway, comparing your log entries to mine, it looks like you have an extra hostname in there: yours: Jun 16 12:53:30 it-vm-99 it-vm-99.my.domain.tld MSWinEventLog[0]:Security 23 Thu Jun 16 12:53:30 2011 592 Security SYSTEM User Success Audit IT-VM-99 Detailed Tracking A new process has been created: New Process ID: 5352 Image File Name: C:\WINDOWS\system32\searchprotocolhost.exe Creator Process ID: 1032 User Name: IT-VM-99$ Domain: MY Logon ID: (0x0,0x3E7) 12 mine: Jun 26 06:19:45 TONKA MSWinEventLog 1 Application 429 Sun Jun 26 06:19:45 2011 15 AutoEnrollment Unknown User N/A Error TONKA None Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b). The specified domain either does not exist or could not be contacted. Enrollment will not be performed. 160 I'm curious to know where the extra fully qualified hostname is coming from, snare or syslog. I think I'm using an earlier version of snare too. Could you post a full packet dump of one packet? In any case, we probably should fix the scripts to handle either format. I'll try to take a look. -- Orion Poplawski Technical Manager 303-415-9701 x222 NWRA/CoRA Division FAX: 303-415-9702 3380 Mitchell Lane [email protected] Boulder, CO 80301 http://www.cora.nwra.com ------------------------------------------------------------------------------ All of the data generated in your IT infrastructure is seriously valuable. Why? It contains a definitive record of application performance, security threats, fraudulent activity, and more. Splunk takes this data and makes sense of it. IT sense. And common sense. http://p.sf.net/sfu/splunk-d2d-c2