Re: prelude-lml and syslog message over the network

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <1247234165.31201.37.camel@arwen>
Hi,

Le lundi 16 mars 2009 à 16:44 +0100, [email protected] a écrit :
> I am setting up PreludeIDS, and I am having a bit of a trouble with prelude-lml, on CentOS.
> 
> Basically, I have initially set syslog to accept messages over the network and log them into files. However, because 
> there is quite a lot of syslog traffic, I wanted to setup prelude-lml as a listener, so that I can only accept+log 
> (into prelude db) events that I need.
> 
> Problem that I have is:
> 
> 16 Mar 11:04:20 (process:8776) WARNING: no appropriate format defined for log entry: 'sshd[24034]: 
> pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=172.18.100.1  user=root
> 
> Trouble is that this message doesn't have timestamp and hostname, which are fields defined in syslog format. 

That's an interesting log entry, where is this coming from? 

> I have 
> tried defining 'custom' format, without timestamp/hostname, but then entries show up (in prewikka) with 
> 'destination' of 127.0.0.1.
> 
> What is the proper way to handle a case like this?

Unfortunately, none at the moment. The problem is that Prelude-LML won't
rely on the sender IP address, since the message might have been relayed
from yet another machine.

I agree it would be nice to have this behavior as an option through...
You might want to open a feature request on https://dev.prelude-ids.com
if you are interested.

Regards,

-- 
Yoann Vandoorselaere <[email protected]>

_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.