ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Solved Wazuh - operational and can add agents - now what

    IT Discussion
    wazuh windows log management alerts
    3
    23
    3.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ @DustinB3403
      last edited by

      @DustinB3403 said in Wazuh - operational and can add agents - now what:

      @IRJ

      Starting Wazuh manager...
      env[11414]: 2019/12/11 13:57:27 ossec-analysisd: CRITICAL: rules_list: Signature ID '13202' not found. Invalid 'if_sid'.
      env[11414]: ossec-analysisd: Configuration error. Exiting
      systemd[1]: wazuh-manager.service: Control process exited, code=exited status=1
      systemd[1]: wazuh-manager.service: Failed with result 'exit-code'.
      systemd[1]: Failed to start Wazuh manager.

      Does rule 13202 not exist? you should be able to find it in your rules folder under 0200-smbd_rules.xml file

      1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403 @Dashrender
        last edited by

        @Dashrender

        Starting Wazuh manager...
         env[11593]: 2019/12/11 15:11:32 ossec-analysisd: CRITICAL: rules_list: Signature ID '9999' not found. Invalid 'if_sid'.
         env[11593]: ossec-analysisd: Configuration error. Exiting
         systemd[1]: wazuh-manager.service: Control process exited, code=exited status=1
         systemd[1]: wazuh-manager.service: Failed with result 'exit-code'.
         systemd[1]: Failed to start Wazuh manager.
        
        IRJI 1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ @DustinB3403
          last edited by

          @DustinB3403 said in Wazuh - operational and can add agents - now what:

          @Dashrender

          Starting Wazuh manager...
           env[11593]: 2019/12/11 15:11:32 ossec-analysisd: CRITICAL: rules_list: Signature ID '9999' not found. Invalid 'if_sid'.
           env[11593]: ossec-analysisd: Configuration error. Exiting
           systemd[1]: wazuh-manager.service: Control process exited, code=exited status=1
           systemd[1]: wazuh-manager.service: Failed with result 'exit-code'.
           systemd[1]: Failed to start Wazuh manager.
          

          Oh I made a typo! Its supposed to be 13102

          1 Reply Last reply Reply Quote 0
          • IRJI
            IRJ
            last edited by IRJ

            @DustinB3403

            This is how you verify rule ID numbers

            c2826081-0d96-4382-a777-fa5644cf47e9-image.png

            Then you open the rule file

            bf7fbc92-da9a-4ee0-b147-9baee6dd8646-image.png

            1 Reply Last reply Reply Quote 1
            • DustinB3403D
              DustinB3403
              last edited by

              @IRJ so a lot of this works out of the box, one question I have is how the heck do I get the details of specific events.

              In the below I specifically failed a login attempt a few times, How can I find out what client was attempting to login to this server and failed?

              chrome_43H3sn69pw.png

              IRJI 1 Reply Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403
                last edited by

                Or I guess an even better question is there some free training on wazuh? I did a very brief search and found a few things, but it's all over the place as to what may be useful.

                IRJI 1 Reply Last reply Reply Quote 0
                • IRJI
                  IRJ @DustinB3403
                  last edited by

                  @DustinB3403 said in Wazuh - operational and can add agents - now what:

                  @IRJ so a lot of this works out of the box, one question I have is how the heck do I get the details of specific events.

                  In the below I specifically failed a login attempt a few times, How can I find out what client was attempting to login to this server and failed?

                  chrome_43H3sn69pw.png

                  So you already filtered it. Just click discover on top right

                  DustinB3403D 1 Reply Last reply Reply Quote 0
                  • IRJI
                    IRJ @DustinB3403
                    last edited by

                    @DustinB3403 said in Wazuh - operational and can add agents - now what:

                    Or I guess an even better question is there some free training on wazuh? I did a very brief search and found a few things, but it's all over the place as to what may be useful.

                    Nope, I should make a course on Udemy, though

                    1 Reply Last reply Reply Quote 0
                    • DustinB3403D
                      DustinB3403 @IRJ
                      last edited by DustinB3403

                      @IRJ said in Wazuh - operational and can add agents - now what:

                      So you already filtered it. Just click discover on top right

                      Doh that is so easy that I didn't even think that was it.

                      IRJI 1 Reply Last reply Reply Quote 0
                      • IRJI
                        IRJ @DustinB3403
                        last edited by

                        @DustinB3403 said in Wazuh - operational and can add agents - now what:

                        @IRJ said in Wazuh - operational and can add agents - now what:

                        So you already filtered it. Just click discover on top right

                        Doh that is so easy that I didn't even think that was it.

                        @DustinB3403

                        3a8e8726-f742-493d-a2cd-5f54c82ce4fb-image.png

                        1 Reply Last reply Reply Quote 0
                        • 1
                        • 2
                        • 2 / 2
                        • First post
                          Last post