Re: Issue with scripts/services/evt[application|security|system]
William Voyek <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Jun 29, 2011 at 11:48 AM, Orion Poplawski <[email protected]> wrote: > Wow, interesting to hear of someone else actually trying to use this code. > > Anyway, comparing your log entries to mine, it looks like you have an extra > hostname in there: > > yours: > Jun 16 12:53:30 it-vm-99 it-vm-99.my.domain.tld MSWinEventLog[0]:Security > 23 Thu Jun 16 12:53:30 2011 592 Security SYSTEM > User Success Audit IT-VM-99 Detailed Tracking A new > process has been created: New Process ID: 5352 Image File Name: > C:\WINDOWS\system32\searchprotocolhost.exe Creator Process ID: 1032 > User Name: IT-VM-99$ Domain: MY Logon ID: (0x0,0x3E7) 12 > > > mine: > Jun 26 06:19:45 TONKA MSWinEventLog 1 Application 429 Sun > Jun 26 06:19:45 2011 15 AutoEnrollment Unknown User N/A > Error TONKA None Automatic certificate enrollment for local > system failed to contact the active directory (0x8007054b). The specified > domain either does not exist or could not be contacted. Enrollment will not > be performed. 160 > > I'm curious to know where the extra fully qualified hostname is coming from, > snare or syslog. I think I'm using an earlier version of snare too. Could > you post a full packet dump of one packet? In any case, we probably should > fix the scripts to handle either format. I'll try to take a look. It appears that the FQDN is comming from the Windows machine. Here is the packet data as captured from the Windows box: Jun 29 13:10:31 it-vm-99.my.domain.tld MSWinEventLog[1]:Security 20841 Wed Jun 29 13:10:25 2011 529 Security SYSTEM User Failure Audit IT-VM-99 Logon/Logoff Logon Failure: Reason: Unknown user name or bad password User Name: baduser Domain: MY Logon Type: 2 Logon Process: seclogon Authentication Package: Negotiate Workstation Name: IT-VM-99 20448 And the same event on the syslog server: Jun 29 13:10:31 it-vm-99 it-vm-99.my.domain.tld MSWinEventLog[1]:Security 20841 Wed Jun 29 13:10:25 2011 529 Security SYSTEM User Failure Audit IT-VM-99 Logon/Logoff Logon Failure: Reason: Unknown user name or bad password User Name: baduser Domain: MY Logon Type: 2 Logon Process: seclogon Authentication Package: Negotiate Workstation Name: IT-VM-99 20448 I have attached the packet I captured on the Windows machine ------------------------------------------------------------------------------ All of the data generated in your IT infrastructure is seriously valuable. Why? It contains a definitive record of application performance, security threats, fraudulent activity, and more. Splunk takes this data and makes sense of it. IT sense. And common sense. http://p.sf.net/sfu/splunk-d2d-c2 _______________________________________________ Logwatch-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/logwatch-devel
syslog_capture.pcap
(application/octet-stream, 483 B) - not displayed