Re: Issue with scripts/services/evt[application|security|system]
Orion Poplawski <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
On 06/29/2011 02:36 PM, William Voyek wrote: > On Wed, Jun 29, 2011 at 11:48 AM, Orion Poplawski<[email protected]> wrote: >> I'm curious to know where the extra fully qualified hostname is coming from, >> snare or syslog. I think I'm using an earlier version of snare too. Could >> you post a full packet dump of one packet? In any case, we probably should >> fix the scripts to handle either format. I'll try to take a look. > > It appears that the FQDN is comming from the Windows machine. Here is > the packet data as captured from the Windows box: > Jun 29 13:10:31 it-vm-99.my.domain.tld > MSWinEventLog[1]:Security 20841 Wed Jun 29 13:10:25 > 2011 529 Security SYSTEM User Failure > Audit IT-VM-99 Logon/Logoff Logon Failure: Reason: Unknown user > name or bad password User Name: baduser Domain: MY Logon > Type: 2 Logon Process: seclogon Authentication Package: > Negotiate Workstation Name: IT-VM-99 20448 > > And the same event on the syslog server: > > Jun 29 13:10:31 it-vm-99 it-vm-99.my.domain.tld > MSWinEventLog[1]:Security 20841 Wed Jun 29 13:10:25 > 2011 529 Security SYSTEM User Failure > Audit IT-VM-99 Logon/Logoff Logon Failure: Reason: Unknown user > name or bad password User Name: baduser Domain: MY Logon > Type: 2 Logon Process: seclogon Authentication Package: > Negotiate Workstation Name: IT-VM-99 20448 > > > I have attached the packet I captured on the Windows machine There still is something interesting on the syslog server that ends up putting in the hostname twice. What is the name of your syslog server? Are you running syslog or rsyslog? Could to attach the relevant (r)syslog.conf file? Not a big deal at this point as I've basically changed the logwatch scripts to ignore everything before the MSWinEventLog string. But I am interested in exploring issues with logwatch and syslog servers. It appears that at the moment logwatch throws away the initial host name. And I suspect lots of things break when there are two hostnames. -- Orion Poplawski Technical Manager 303-415-9701 x222 NWRA/CoRA Division FAX: 303-415-9702 3380 Mitchell Lane [email protected] Boulder, CO 80301 http://www.cora.nwra.com ------------------------------------------------------------------------------ All of the data generated in your IT infrastructure is seriously valuable. Why? It contains a definitive record of application performance, security threats, fraudulent activity, and more. Splunk takes this data and makes sense of it. IT sense. And common sense. http://p.sf.net/sfu/splunk-d2d-c2