prelude-lml regex help.
la Bigmac <[email protected]> Thu, 6 Jan 2011 12:01:57 +0000
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
Hello list, I have configured prelude and prelude-lml to work on a couple of syslog hosts. = At present I am just trying to keep it simple and look for successful and unsuccessful logon events. = My various devices are all centrally logging and I can see the login events in the syslog files. I have configured prelude-lml to monitor 2 files /var/log/auth.log /var/log/remote/cisco.log = The issue I am seeing is login events to my linux box (auth.log) are reported to prewikka just fine, but events to cisco.log are = not being reported. = To confirm I had setup the monitoring of the cisco.log file within prelude-lml I setup a tail =96f /var/log/auth.log >> /var/log/remote/cisco.log so all the login event of my linux box were copie= d to cisco.log this worked and the events were reported to prewikka. = My assumption is that I need to look at adding a new regex to single.rules to =91capture=92 the login events. = The logon events I am looking for are ssh events to a Cisco switch (Nexus 7000) the syslog entry is as follows: Jan 6 11:33:00 192.168.x.x : 2011 Jan 6 11:34:18 GMT: %DAEMON-3-SYSTEM_MSG: error: PAM: Authentication failure for illegal user wrong5 from 192.168.x.x - sshd[19191] I am too embarrassed to post my attempt at a regex=85 Am I right to continue to work on my regex in single.rules (any help is very welcome) or am I missing something obvious.. = Regards, Mat. = = _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-technologies.com/mailman/listinfo/prelude-user