prelude-lml regex help.

la Bigmac <[email protected]> Thu, 6 Jan 2011 12:01:57 +0000
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>


Hello list,


I have configured prelude and prelude-lml to work on a couple
of syslog hosts. =


At present I am just trying to keep it simple and look for successful
and unsuccessful logon events. =



My various devices are all centrally logging and I can see
the login events in the syslog files.


I have configured prelude-lml to monitor 2 files

/var/log/auth.log

/var/log/remote/cisco.log

 =


The issue I am seeing is login events to my linux box
(auth.log) are reported to prewikka just fine, but events to cisco.log are =
not
being reported. =



To confirm I had setup the monitoring of the cisco.log file
within prelude-lml I setup a tail =96f /var/log/auth.log >>
/var/log/remote/cisco.log so all the login event of my linux box were copie=
d to
cisco.log this worked and the events were reported to prewikka. =



My assumption is that I need to look at adding a new regex
to single.rules to =91capture=92 the login events. =



The logon events I am looking for are ssh events to a Cisco
switch (Nexus 7000) the syslog entry is as follows:

Jan  6 11:33:00
192.168.x.x : 2011 Jan  6 11:34:18 GMT:
%DAEMON-3-SYSTEM_MSG: error: PAM: Authentication failure for illegal user
wrong5 from 192.168.x.x - sshd[19191]


I am too embarrassed to post my attempt at a regex=85


Am I right to continue to work on my regex in single.rules
(any help is very welcome) or am I missing something obvious.. =



Regards,


Mat. =


 		 	   		  =

_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-technologies.com/mailman/listinfo/prelude-user