-
Notifications
You must be signed in to change notification settings - Fork 203
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Review FortiOS decoders and rules #168
Comments
It seems that some of the logs that were contributed to the work was the incorrect level. Example, log supplied: and Actual log from Fortios 5.6 Here is the updated UTM/IPS Decoder: |
and another one :(, fixed decoder for traffic.
|
So I had to adjust the UTM one final time to get it to read the different syslog events with same type and subtype classification but different fields. This regex works
|
@jesuslinares @SitoRBJ Hi Guys. Need some assistance with the traffic decoder please. Original Decoder: Custom Decoder: Full log example:
Partial Log Example:
I have tried every possible combination but nothing seems to be able to grab the fields. Not sure if this is an ordering sequence issue or just staring too long at the same thing. It did however match the parent. I had two decoders initially (one for partial log and one for full log). Any suggestions are welcome. |
Hello @LFBernardo , First of all, I want to apologize for the delay and for any problems you may have had with the delay. We have a PR that fixes Fortigate's decoders: #147 We have tested the events you have provided us with the rules and decoders of that PR and they seem to be working properly. For example:
We have tried quite a few formats and types of Fortigate events and will accept the PR soon. If you want, you can test whether the events you receive generate alerts correctly. Thank you very much for your contribution, the collaboration of the community is indispensable for us. Kind regards, Alfonso Ruiz-Bravo |
Thanks Alfonso, I will try the updated set in your above post and let you know. Still having difficulty with the type="traffic" events. Will also check for that. |
I have the following fields defined as per the standard set by FRGV. They work with my logs if you want to consider adding them as well? ` |
Hello @LFBernardo, Thank you very much for your collaboration, as you know, for us the contributions of the community are essential to continue growing. We will probably add the decoders to get your fields as soon as possible. Kind regards, Alfonso Ruiz-Bravo |
Thanks Alfonso, the feedback is appreciated. |
Hello @LFBernardo, We have updated the PR of fortigate: #147 We proceed to close the issue, please do not hesitate to ask us any questions. Thank you very much for your collaboration. Kind regards, Alfonso Ruiz-Bravo |
Review this contribution in wazuh-list for FortiOS:
https://groups.google.com/forum/#!topic/wazuh/1N-1IeWNTIg
Thanks Louis.
The text was updated successfully, but these errors were encountered: