Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix truncated "action" on certain Cisco PIX/ASA logs #668

Merged
merged 12 commits into from
Sep 29, 2015

Conversation

brentmorris253
Copy link
Contributor

This fixes the Cisco decoder from truncating the action. Prior to this change, the decoder only picks up the first letter of the word 'denied'.

This can be verified with the existing sample logs - %PIX-3-710003: TCP access denied by ACL from 216.39.220.130/54065 to outside:62.192.113.98/ssh

This fixes the Cisco decoder from truncating the action.  Prior to this change, the decoder only picks up the first letter of the word 'denied'.

This can be verified with the existing sample logs - %PIX-3-710003: TCP access denied by ACL from 216.39.220.130/54065 to outside:62.192.113.98/ssh
Fix truncated "action" on Cisco PIX/ASA
@brentmorris253
Copy link
Contributor Author

Sorry, I am new to github. This should be two pull requests. One fixing the pix rules and one fixing the ms-se_rules.xml

Added events for TS Gateway - https://technet.microsoft.com/en-us/library/cc775181(v=ws.10).aspx

OSSEC client agent needs to monitor Microsoft-Windows-TerminalServices-Gateway/Operational event channel to receive these.
Include TS Gateway Events in msauth_rules.xml
…ch-4

Revert "Include TS Gateway Events in msauth_rules.xml"
ddpbsd added a commit that referenced this pull request Sep 29, 2015
Fix truncated "action" on certain Cisco PIX/ASA logs
@ddpbsd ddpbsd merged commit 52ff934 into ossec:master Sep 29, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants