Skip to content
This repository has been archived by the owner on Apr 19, 2021. It is now read-only.

Add source of syslog as destination IP for Sguil alert #5

Merged
merged 2 commits into from
Jul 3, 2015

Conversation

theflakes
Copy link
Contributor

Some syslogs do not contain the IP of the device sending the syslog in the body of the syslog. Cisco ASAs do this with some syslog messages. Therefore I added to the regex to pull this information out if it exists in the second line of the OSSEC alert.

theflakes added 2 commits June 3, 2015 20:42
Some syslogs do not contain the IP of the device sending the syslog in the body of the syslog.  Cisco ASAs do this with some syslog messages.  Therefore I added to the regex to pull this information out if it exists in the second line of the OSSEC alert.
@dougburks
Copy link
Contributor

Thanks, Brian! I'll take a look at this as time allows.

@theflakes
Copy link
Contributor Author

Thanks, it still needs some work and I haven’t had time to get back to testing it more yet. I’m not that familiar with the Sguil DB yet so not sure if the set event is set up correctly or not.

On a side note going to start looking at some point into adding a username column to Sguil. That would be very useful for OSSEC alerts and finding/correlating credential misuse. Probably a ways away from doing anything with this but the more I work with Sguil and OSSEC the more I see the need for this. ELSA parsers for pulling usernames out is another thing on my list as well.

On Jun 6, 2015, at 10:06 AM, Doug Burks [email protected] wrote:

Thanks, Brian! I'll take a look at this as time allows.


Reply to this email directly or view it on GitHub #5 (comment).

@theflakes
Copy link
Contributor Author

Sorry Doug, thought this email was on the Squil Bro-agent.

The Github pull request for the ossec-agent update should be good to go for testing whenever you are ready.

On Jun 6, 2015, at 10:06 AM, Doug Burks [email protected] wrote:

Thanks, Brian! I'll take a look at this as time allows.


Reply to this email directly or view it on GitHub #5 (comment).

dougburks added a commit that referenced this pull request Jul 3, 2015
Add source of syslog as destination IP for Sguil alert
@dougburks dougburks merged commit 977b883 into Security-Onion-Solutions:master Jul 3, 2015
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants