Re: Issue with scripts/services/evt[application|security|system]

Orion Poplawski <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
On 06/29/2011 02:36 PM, William Voyek wrote:
> On Wed, Jun 29, 2011 at 11:48 AM, Orion Poplawski<[email protected]>  wrote:
>> I'm curious to know where the extra fully qualified hostname is coming from,
>> snare or syslog.  I think I'm using an earlier version of snare too.  Could
>> you post a full packet dump of one packet?  In any case, we probably should
>> fix the scripts to handle either format.  I'll try to take a look.
>
> It appears that the FQDN is comming from the Windows machine. Here is
> the packet data as captured from the Windows box:
> Jun 29 13:10:31 it-vm-99.my.domain.tld
> MSWinEventLog[1]:Security	20841	Wed Jun 29 13:10:25
> 2011	529	Security	SYSTEM	User	Failure
> Audit	IT-VM-99	Logon/Logoff		Logon Failure:     Reason: Unknown user
> name or bad password     User Name: baduser     Domain: MY     Logon
> Type: 2     Logon Process: seclogon     Authentication Package:
> Negotiate     Workstation Name: IT-VM-99  	20448
>
> And the same event on the syslog server:
>
> Jun 29 13:10:31 it-vm-99 it-vm-99.my.domain.tld
> MSWinEventLog[1]:Security	20841	Wed Jun 29 13:10:25
> 2011	529	Security	SYSTEM	User	Failure
> Audit	IT-VM-99	Logon/Logoff		Logon Failure:     Reason: Unknown user
> name or bad password     User Name: baduser     Domain: MY     Logon
> Type: 2     Logon Process: seclogon     Authentication Package:
> Negotiate     Workstation Name: IT-VM-99  	20448
>
>
> I have attached the packet I captured on the Windows machine

There still is something interesting on the syslog server that ends up putting 
in the hostname twice.  What is the name of your syslog server?  Are you 
running syslog or rsyslog?  Could to attach the relevant (r)syslog.conf file?

Not a big deal at this point as I've basically changed the logwatch scripts to 
ignore everything before the MSWinEventLog string.  But I am interested in 
exploring issues with logwatch and syslog servers.  It appears that at the 
moment logwatch throws away the initial host name.  And I suspect lots of 
things break when there are two hostnames.

-- 
Orion Poplawski
Technical Manager                     303-415-9701 x222
NWRA/CoRA Division                    FAX: 303-415-9702
3380 Mitchell Lane                  [email protected]
Boulder, CO 80301              http://www.cora.nwra.com

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.