Re: Issue with scripts/services/evt[application|security|system]

William Voyek <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
On Wed, Jun 29, 2011 at 11:48 AM, Orion Poplawski <[email protected]> wrote:
> Wow, interesting to hear of someone else actually trying to use this code.
>
> Anyway, comparing your log entries to mine, it looks like you have an extra
> hostname in there:
>
> yours:
> Jun 16 12:53:30 it-vm-99 it-vm-99.my.domain.tld MSWinEventLog[0]:Security
>   23      Thu Jun 16 12:53:30 2011        592     Security        SYSTEM
> User    Success Audit   IT-VM-99        Detailed Tracking               A new
> process has been created:     New Process ID: 5352     Image File Name:
> C:\WINDOWS\system32\searchprotocolhost.exe     Creator Process ID: 1032
> User Name: IT-VM-99$     Domain: MY     Logon ID: (0x0,0x3E7)         12
>
>
> mine:
> Jun 26 06:19:45 TONKA MSWinEventLog     1       Application     429     Sun
> Jun 26 06:19:45 2011        15      AutoEnrollment  Unknown User    N/A
> Error   TONKA   None            Automatic certificate enrollment for local
> system failed to contact the active directory (0x8007054b).  The specified
> domain either does not exist or could not be contacted.  Enrollment will not
> be performed.        160
>
> I'm curious to know where the extra fully qualified hostname is coming from,
> snare or syslog.  I think I'm using an earlier version of snare too.  Could
> you post a full packet dump of one packet?  In any case, we probably should
> fix the scripts to handle either format.  I'll try to take a look.

It appears that the FQDN is comming from the Windows machine. Here is
the packet data as captured from the Windows box:
Jun 29 13:10:31 it-vm-99.my.domain.tld
MSWinEventLog[1]:Security	20841	Wed Jun 29 13:10:25
2011	529	Security	SYSTEM	User	Failure
Audit	IT-VM-99	Logon/Logoff		Logon Failure:     Reason: Unknown user
name or bad password     User Name: baduser     Domain: MY     Logon
Type: 2     Logon Process: seclogon     Authentication Package:
Negotiate     Workstation Name: IT-VM-99  	20448

And the same event on the syslog server:

Jun 29 13:10:31 it-vm-99 it-vm-99.my.domain.tld
MSWinEventLog[1]:Security	20841	Wed Jun 29 13:10:25
2011	529	Security	SYSTEM	User	Failure
Audit	IT-VM-99	Logon/Logoff		Logon Failure:     Reason: Unknown user
name or bad password     User Name: baduser     Domain: MY     Logon
Type: 2     Logon Process: seclogon     Authentication Package:
Negotiate     Workstation Name: IT-VM-99  	20448


I have attached the packet I captured on the Windows machine

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2

_______________________________________________
Logwatch-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/logwatch-devel
syslog_capture.pcap (application/octet-stream, 483 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.