Re: Issue with scripts/services/evt[application|security|system]

Orion Poplawski <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
On 06/28/2011 02:56 PM, William Voyek wrote:
> Hello All,
>
> I'm having an issue with the Windows Event Log parsing scripts. I have
> a syslog server with a fresh install of CentOS 5.6 with the latest
> version of Logwatch (7.4.0).
>
> I have attached the logfile to this email.
>
> Can someone can help me correct this either on the SNARE end or the
> logwatch end?

Wow, interesting to hear of someone else actually trying to use this code.

Anyway, comparing your log entries to mine, it looks like you have an extra 
hostname in there:

yours:
Jun 16 12:53:30 it-vm-99 it-vm-99.my.domain.tld MSWinEventLog[0]:Security 
   23      Thu Jun 16 12:53:30 2011        592     Security        SYSTEM 
User    Success Audit   IT-VM-99        Detailed Tracking               A new 
process has been created:     New Process ID: 5352     Image File Name: 
C:\WINDOWS\system32\searchprotocolhost.exe     Creator Process ID: 1032 
User Name: IT-VM-99$     Domain: MY     Logon ID: (0x0,0x3E7)         12 


mine:
Jun 26 06:19:45 TONKA MSWinEventLog     1       Application     429     Sun 
Jun 26 06:19:45 2011        15      AutoEnrollment  Unknown User    N/A 
Error   TONKA   None            Automatic certificate enrollment for local 
system failed to contact the active directory (0x8007054b).  The specified 
domain either does not exist or could not be contacted.  Enrollment will not 
be performed.        160

I'm curious to know where the extra fully qualified hostname is coming from, 
snare or syslog.  I think I'm using an earlier version of snare too.  Could 
you post a full packet dump of one packet?  In any case, we probably should 
fix the scripts to handle either format.  I'll try to take a look.

-- 
Orion Poplawski
Technical Manager                     303-415-9701 x222
NWRA/CoRA Division                    FAX: 303-415-9702
3380 Mitchell Lane                  [email protected]
Boulder, CO 80301              http://www.cora.nwra.com

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.