[prev in list] [next in list] [prev in thread] [next in thread] 

List:       ossec-list
Subject:    Re: [ossec-list] Rule 1003 flooding
From:       Mark M <plaktau () gmail ! com>
Date:       2018-06-29 21:04:06
Message-ID: ee404733-ab15-4dc4-bb53-6355114d2018 () googlegroups ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


Even at 2048 I get occasional hits.  :-\

On Wednesday, June 27, 2018 at 5:48:44 AM UTC-7, dan (ddpbsd) wrote:
> 
> On Mon, Jun 25, 2018 at 2:55 PM, Mark M <pla...@gmail.com <javascript:>> 
> wrote: 
> > 
> > Thanks Dan. Should I titrate the number down as far as possible, or does 
> it 
> > matter really? 
> > 
> 
> I'm not sure it matters too much. OSSEC needs to move forward at some 
> point. 
> 2048 seems reasonable. 
> 
> > 
> > On Saturday, June 23, 2018 at 2:59:25 PM UTC-7, dan (ddpbsd) wrote: 
> > > 
> > > On Fri, Jun 22, 2018 at 8:19 PM, Mark M <pla...@gmail.com> wrote: 
> > > > 
> > > > Since going to CentOS 7, and installing BigFix on all systems I get a 
> > > > LOT of 
> > > > syslog rule 1003 (file too large) messages. 
> > > > 
> > > > <rule id="1003" level="13" maxsize="1025"> 
> > > > <description>Non standard syslog message (size too 
> > > > large).</description> 
> > > > </rule> 
> > > > 
> > > > What was used to determine the 1025 number? Is this meant to be 
> > > > adjusted, or 
> > > > is it a moving target for the maintainers that needs to be revisited? 
> > > > 
> > > 
> > > In the past syslog was limited to 1024 bytes,s o longer messages 
> > > didn't follow the rules. This can probably be adjusted now. 
> > > I think some of the OSSEC internals may still be limited to 1024 
> > > though, so these would eventually have to be raised (but I haven't 
> > > looked 
> > > at this in a while, so I could be remembering old info) 
> > > 
> > > > OSSEC Log sample: 
> > > > 
> > > > ** Alert 1529706477.1462418: mail  - syslog,errors, 
> > > > 2018 Jun 22 15:27:57 (aspen) xxx.xxx.xxx.xxx->/var/log/secure 
> > > > Rule: 1003 (level 13) -> 'Non standard syslog message (size too 
> large).' 
> > > > Jun 22 15:27:57 aspen audisp-graylog: 
> > > > {"audit_category":"write","audit_summary":"Write: 
> > > > 
> > > > 
> /var/opt/BESClient/__BESData/__Global/UsageData/pickup.stat","audit_hostname":"xxx.x \
> xx.xxx.xxx","audit_timestamp":"2018-06-22T15:27:57-0700","audit_plugin":"audisp-gray \
> log","audit_version":"1.0.0","audit":{"serial":"757820","rdev":"00:00","ogid":"0","o \
> uid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt/BESClient/ \
> __BESData/__Global/UsageData/pickup.stat","serial":"757820","rdev":"00:00","ogid":"0 \
> ","ouid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt/BESCli \
> ent/__BESData/__Global/UsageData/pickup.stattmp","serial":"757820","rdev":"00:00","o \
> gid":"0","ouid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt \
> /BESClient/__BESData/__Global/UsageData/","serial":"757820","rdev":"00:00","ogid":"0 \
> ","ouid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt/BESCli \
> ent/__BESData/__Global/UsageData/","serial":"757820","cwd":"/home/mmoorcro","serial" \
> :"757820","session":"356","fsgid":"0","sgid":"0","egid":"0","fsuid":"0","suid":"0"," \
> euid":"0","gid":"0","pid":"104939","ppid":"1","process":"/opt/BESClient/bin/BESClient","tty":"(none)","uid":"0","user":"root","originaluid":"853945932","orig \
>  
> > > > 
> > > > 
> > > > Actual log event: 
> > > > 
> > > > Jun 22 15:27:57 aspen audisp-graylog: 
> > > > {"audit_category":"write","audit_summary":"Write: 
> > > > 
> > > > 
> /var/opt/BESClient/__BESData/__Global/UsageData/pickup.stat","audit_hostname":"xxx.x \
> xx.xxx.xxx","audit_timestamp":"2018-06-22T15:27:57-0700","audit_plugin":"audisp-gray \
> log","audit_version":"1.0.0","audit":{"serial":"757820","rdev":"00:00","ogid":"0","o \
> uid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt/BESClient/ \
> __BESData/__Global/UsageData/pickup.stat","serial":"757820","rdev":"00:00","ogid":"0 \
> ","ouid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt/BESCli \
> ent/__BESData/__Global/UsageData/pickup.stattmp","serial":"757820","rdev":"00:00","o \
> gid":"0","ouid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt \
> /BESClient/__BESData/__Global/UsageData/","serial":"757820","rdev":"00:00","ogid":"0 \
> ","ouid":"0","mode":"040700","dev":"fd:06","inode":"8716650","path":"/var/opt/BESCli \
> ent/__BESData/__Global/UsageData/","serial":"757820","cwd":"/home/mmoorcro","serial" \
> :"757820","session":"356","fsgid":"0","sgid":"0","egid":"0","fsuid":"0","suid":"0"," \
> euid":"0","gid":"0","pid":"104939","ppid":"1","process":"/opt/BESClient/bin/BESClien \
> t","tty":"(none)","uid":"0","user":"root","originaluid":"853945932","originaluser":" \
> mmoorcro","parentprocess":"systemd","auditkey":"delete","processname":"BESClient","serial":"757820"}} \
>  
> > > > 
> > > > 
> > > > I grant you that the audisp-graylog plugin has some issues. 
> > > > Unfortunately 
> > > > the author is probably never going to look at it again. Regardless, 
> if I 
> > > > double 1025 to 2048, the 1003 messages stop. I'm also wondering about 
> > > > the 
> > > > messages being truncated in the OSSEC log. Presumably changes to the 
> > > > syslog 
> > > > rule may get overwritten at any time. 
> > > > 
> > > > -- 
> > > > 
> > > > --- 
> > > > You received this message because you are subscribed to the Google 
> > > > Groups 
> > > > "ossec-list" group. 
> > > > To unsubscribe from this group and stop receiving emails from it, 
> send 
> > > > an 
> > > > email to ossec-list+...@googlegroups.com. 
> > > > For more options, visit https://groups.google.com/d/optout. 
> > 
> > -- 
> > 
> > --- 
> > You received this message because you are subscribed to the Google 
> Groups 
> > "ossec-list" group. 
> > To unsubscribe from this group and stop receiving emails from it, send 
> an 
> > email to ossec-list+...@googlegroups.com <javascript:>. 
> > For more options, visit https://groups.google.com/d/optout. 
> 

-- 

--- 
You received this message because you are subscribed to the Google Groups \
"ossec-list" group. To unsubscribe from this group and stop receiving emails from it, \
send an email to ossec-list+unsubscribe@googlegroups.com. For more options, visit \
https://groups.google.com/d/optout.


[Attachment #5 (text/html)]

<div dir="ltr"><br>Even at 2048 I get occasional hits.   :-\<br><br>On Wednesday, \
June 27, 2018 at 5:48:44 AM UTC-7, dan (ddpbsd) wrote:<blockquote class="gmail_quote" \
style="margin: 0;margin-left: 0.8ex;border-left: 1px #ccc solid;padding-left: \
1ex;">On Mon, Jun 25, 2018 at 2:55 PM, Mark M &lt;<a href="javascript:" \
target="_blank" gdf-obfuscated-mailto="zcYto4xaCgAJ" rel="nofollow" \
onmousedown="this.href=&#39;javascript:&#39;;return true;" \
onclick="this.href=&#39;javascript:&#39;;return true;">pla...@gmail.com</a>&gt; \
wrote: <br>&gt;
<br>&gt; Thanks Dan. Should I titrate the number down as far as possible, or does it
<br>&gt; matter really?
<br>&gt;
<br>
<br>I&#39;m not sure it matters too much. OSSEC needs to move forward at some point.
<br>2048 seems reasonable.
<br>
<br>&gt;
<br>&gt; On Saturday, June 23, 2018 at 2:59:25 PM UTC-7, dan (ddpbsd) wrote:
<br>&gt;&gt;
<br>&gt;&gt; On Fri, Jun 22, 2018 at 8:19 PM, Mark M &lt;<a>pla...@gmail.com</a>&gt; \
wrote: <br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; Since going to CentOS 7, and installing BigFix on all systems I get \
a <br>&gt;&gt; &gt; LOT of
<br>&gt;&gt; &gt; syslog rule 1003 (file too large) messages.
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt;    &lt;rule id=&quot;1003&quot; level=&quot;13&quot; \
maxsize=&quot;1025&quot;&gt; <br>&gt;&gt; &gt;       &lt;description&gt;Non standard \
syslog message (size too <br>&gt;&gt; &gt; large).&lt;/description&gt;
<br>&gt;&gt; &gt;    &lt;/rule&gt;
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; What was used to determine the 1025 number? Is this meant to be
<br>&gt;&gt; &gt; adjusted, or
<br>&gt;&gt; &gt; is it a moving target for the maintainers that needs to be \
revisited? <br>&gt;&gt; &gt;
<br>&gt;&gt;
<br>&gt;&gt; In the past syslog was limited to 1024 bytes,s o longer messages
<br>&gt;&gt; didn&#39;t follow the rules. This can probably be adjusted now.
<br>&gt;&gt; I think some of the OSSEC internals may still be limited to 1024
<br>&gt;&gt; though, so these would eventually have to be raised (but I haven&#39;t
<br>&gt;&gt; looked
<br>&gt;&gt; at this in a while, so I could be remembering old info)
<br>&gt;&gt;
<br>&gt;&gt; &gt; OSSEC Log sample:
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; ** Alert 1529706477.1462418: mail   - syslog,errors,
<br>&gt;&gt; &gt; 2018 Jun 22 15:27:57 (aspen) \
xxx.xxx.xxx.xxx-&gt;/var/log/<wbr>secure <br>&gt;&gt; &gt; Rule: 1003 (level 13) \
-&gt; &#39;Non standard syslog message (size too large).&#39; <br>&gt;&gt; &gt; Jun \
22 15:27:57 aspen audisp-graylog: <br>&gt;&gt; &gt; \
{&quot;audit_category&quot;:&quot;write&quot;,&quot;<wbr>audit_summary&quot;:&quot;Write:
 <br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; /var/opt/BESClient/__BESData/_<wbr>_Global/UsageData/pickup.stat&quo \
t;<wbr>,&quot;audit_hostname&quot;:&quot;xxx.xxx.<wbr>xxx.xxx&quot;,&quot;audit_timest \
amp&quot;:&quot;<wbr>2018-06-22T15:27:57-0700&quot;,&quot;<wbr>audit_plugin&quot;:&quo \
t;audisp-graylog&quot;<wbr>,&quot;audit_version&quot;:&quot;1.0.0&quot;,&quot;<wbr>aud \
it&quot;:{&quot;serial&quot;:&quot;757820&quot;,&quot;<wbr>rdev&quot;:&quot;00:00&quot \
;,&quot;ogid&quot;:&quot;0&quot;,&quot;<wbr>ouid&quot;:&quot;0&quot;,&quot;mode&quot;: \
&quot;040700&quot;,&quot;<wbr>dev&quot;:&quot;fd:06&quot;,&quot;inode&quot;:&quot;8716 \
650&quot;<wbr>,&quot;path&quot;:&quot;/var/opt/BESClient/__<wbr>BESData/__Global/Usage \
Data/<wbr>pickup.stat&quot;,&quot;serial&quot;:&quot;757820&quot;<wbr>,&quot;rdev&quot \
;:&quot;00:00&quot;,&quot;ogid&quot;:&quot;0&quot;,&quot;<wbr>ouid&quot;:&quot;0&quot; \
,&quot;mode&quot;:&quot;040700&quot;,&quot;<wbr>dev&quot;:&quot;fd:06&quot;,&quot;inod \
e&quot;:&quot;8716650&quot;<wbr>,&quot;path&quot;:&quot;/var/opt/BESClient/__<wbr>BESD \
ata/__Global/UsageData/<wbr>pickup.stattmp&quot;,&quot;serial&quot;:&quot;<wbr>757820& \
quot;,&quot;rdev&quot;:&quot;00:00&quot;,&quot;ogid&quot;:<wbr>&quot;0&quot;,&quot;oui \
d&quot;:&quot;0&quot;,&quot;mode&quot;:&quot;040700&quot;<wbr>,&quot;dev&quot;:&quot;f \
d:06&quot;,&quot;inode&quot;:&quot;<wbr>8716650&quot;,&quot;path&quot;:&quot;/var/opt/ \
<wbr>BESClient/__BESData/__Global/<wbr>UsageData/&quot;,&quot;serial&quot;:&quot;75782 \
0&quot;,<wbr>&quot;rdev&quot;:&quot;00:00&quot;,&quot;ogid&quot;:&quot;0&quot;,&quot;< \
wbr>ouid&quot;:&quot;0&quot;,&quot;mode&quot;:&quot;040700&quot;,&quot;<wbr>dev&quot;: \
&quot;fd:06&quot;,&quot;inode&quot;:&quot;8716650&quot;<wbr>,&quot;path&quot;:&quot;/v \
ar/opt/BESClient/__<wbr>BESData/__Global/UsageData/&quot;,&quot;<wbr>serial&quot;:&quo \
t;757820&quot;,&quot;cwd&quot;:&quot;/home/<wbr>mmoorcro&quot;,&quot;serial&quot;:&quo \
t;757820&quot;,&quot;<wbr>session&quot;:&quot;356&quot;,&quot;fsgid&quot;:&quot;0&quot \
;,&quot;<wbr>sgid&quot;:&quot;0&quot;,&quot;egid&quot;:&quot;0&quot;,&quot;fsuid&quot; \
:&quot;<wbr>0&quot;,&quot;suid&quot;:&quot;0&quot;,&quot;euid&quot;:&quot;0&quot;,&quo \
t;gid&quot;<wbr>:&quot;0&quot;,&quot;pid&quot;:&quot;104939&quot;,&quot;ppid&quot;:&qu \
ot;1&quot;<wbr>,&quot;process&quot;:&quot;/opt/BESClient/<wbr>bin/BESClient&quot;,&quo \
t;tty&quot;:&quot;(none)&quot;,<wbr>&quot;uid&quot;:&quot;0&quot;,&quot;user&quot;:&quot;root&quot;,&quot;<wbr>originaluid&quot;:&quot;853945932&quot;,&quot;orig
 <br>&gt;&gt; &gt;
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; Actual log event:
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; Jun 22 15:27:57 aspen audisp-graylog:
<br>&gt;&gt; &gt; {&quot;audit_category&quot;:&quot;write&quot;,&quot;<wbr>audit_summary&quot;:&quot;Write:
 <br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; /var/opt/BESClient/__BESData/_<wbr>_Global/UsageData/pickup.stat&quo \
t;<wbr>,&quot;audit_hostname&quot;:&quot;xxx.xxx.<wbr>xxx.xxx&quot;,&quot;audit_timest \
amp&quot;:&quot;<wbr>2018-06-22T15:27:57-0700&quot;,&quot;<wbr>audit_plugin&quot;:&quo \
t;audisp-graylog&quot;<wbr>,&quot;audit_version&quot;:&quot;1.0.0&quot;,&quot;<wbr>aud \
it&quot;:{&quot;serial&quot;:&quot;757820&quot;,&quot;<wbr>rdev&quot;:&quot;00:00&quot \
;,&quot;ogid&quot;:&quot;0&quot;,&quot;<wbr>ouid&quot;:&quot;0&quot;,&quot;mode&quot;: \
&quot;040700&quot;,&quot;<wbr>dev&quot;:&quot;fd:06&quot;,&quot;inode&quot;:&quot;8716 \
650&quot;<wbr>,&quot;path&quot;:&quot;/var/opt/BESClient/__<wbr>BESData/__Global/Usage \
Data/<wbr>pickup.stat&quot;,&quot;serial&quot;:&quot;757820&quot;<wbr>,&quot;rdev&quot \
;:&quot;00:00&quot;,&quot;ogid&quot;:&quot;0&quot;,&quot;<wbr>ouid&quot;:&quot;0&quot; \
,&quot;mode&quot;:&quot;040700&quot;,&quot;<wbr>dev&quot;:&quot;fd:06&quot;,&quot;inod \
e&quot;:&quot;8716650&quot;<wbr>,&quot;path&quot;:&quot;/var/opt/BESClient/__<wbr>BESD \
ata/__Global/UsageData/<wbr>pickup.stattmp&quot;,&quot;serial&quot;:&quot;<wbr>757820& \
quot;,&quot;rdev&quot;:&quot;00:00&quot;,&quot;ogid&quot;:<wbr>&quot;0&quot;,&quot;oui \
d&quot;:&quot;0&quot;,&quot;mode&quot;:&quot;040700&quot;<wbr>,&quot;dev&quot;:&quot;f \
d:06&quot;,&quot;inode&quot;:&quot;<wbr>8716650&quot;,&quot;path&quot;:&quot;/var/opt/ \
<wbr>BESClient/__BESData/__Global/<wbr>UsageData/&quot;,&quot;serial&quot;:&quot;75782 \
0&quot;,<wbr>&quot;rdev&quot;:&quot;00:00&quot;,&quot;ogid&quot;:&quot;0&quot;,&quot;< \
wbr>ouid&quot;:&quot;0&quot;,&quot;mode&quot;:&quot;040700&quot;,&quot;<wbr>dev&quot;: \
&quot;fd:06&quot;,&quot;inode&quot;:&quot;8716650&quot;<wbr>,&quot;path&quot;:&quot;/v \
ar/opt/BESClient/__<wbr>BESData/__Global/UsageData/&quot;,&quot;<wbr>serial&quot;:&quo \
t;757820&quot;,&quot;cwd&quot;:&quot;/home/<wbr>mmoorcro&quot;,&quot;serial&quot;:&quo \
t;757820&quot;,&quot;<wbr>session&quot;:&quot;356&quot;,&quot;fsgid&quot;:&quot;0&quot \
;,&quot;<wbr>sgid&quot;:&quot;0&quot;,&quot;egid&quot;:&quot;0&quot;,&quot;fsuid&quot; \
:&quot;<wbr>0&quot;,&quot;suid&quot;:&quot;0&quot;,&quot;euid&quot;:&quot;0&quot;,&quo \
t;gid&quot;<wbr>:&quot;0&quot;,&quot;pid&quot;:&quot;104939&quot;,&quot;ppid&quot;:&qu \
ot;1&quot;<wbr>,&quot;process&quot;:&quot;/opt/BESClient/<wbr>bin/BESClient&quot;,&quo \
t;tty&quot;:&quot;(none)&quot;,<wbr>&quot;uid&quot;:&quot;0&quot;,&quot;user&quot;:&qu \
ot;root&quot;,&quot;<wbr>originaluid&quot;:&quot;853945932&quot;,&quot;<wbr>originalus \
er&quot;:&quot;mmoorcro&quot;,&quot;<wbr>parentprocess&quot;:&quot;systemd&quot;,&quot \
;<wbr>auditkey&quot;:&quot;delete&quot;,&quot;<wbr>processname&quot;:&quot;BESClient&quot;,&quot;<wbr>serial&quot;:&quot;757820&quot;}}
 <br>&gt;&gt; &gt;
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; I grant you that the audisp-graylog plugin has some issues.
<br>&gt;&gt; &gt; Unfortunately
<br>&gt;&gt; &gt; the author is probably never going to look at it again. Regardless, \
if I <br>&gt;&gt; &gt; double 1025 to 2048, the 1003 messages stop. I&#39;m also \
wondering about <br>&gt;&gt; &gt; the
<br>&gt;&gt; &gt; messages being truncated in the OSSEC log. Presumably changes to \
the <br>&gt;&gt; &gt; syslog
<br>&gt;&gt; &gt; rule may get overwritten at any time.
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; --
<br>&gt;&gt; &gt;
<br>&gt;&gt; &gt; ---
<br>&gt;&gt; &gt; You received this message because you are subscribed to the Google
<br>&gt;&gt; &gt; Groups
<br>&gt;&gt; &gt; &quot;ossec-list&quot; group.
<br>&gt;&gt; &gt; To unsubscribe from this group and stop receiving emails from it, \
send <br>&gt;&gt; &gt; an
<br>&gt;&gt; &gt; email to <a>ossec-list+...@googlegroups.<wbr>com</a>.
<br>&gt;&gt; &gt; For more options, visit <a \
href="https://groups.google.com/d/optout" target="_blank" rel="nofollow" \
onmousedown="this.href=&#39;https://groups.google.com/d/optout&#39;;return true;" \
onclick="this.href=&#39;https://groups.google.com/d/optout&#39;;return \
true;">https://groups.google.com/d/<wbr>optout</a>. <br>&gt;
<br>&gt; --
<br>&gt;
<br>&gt; ---
<br>&gt; You received this message because you are subscribed to the Google Groups
<br>&gt; &quot;ossec-list&quot; group.
<br>&gt; To unsubscribe from this group and stop receiving emails from it, send an
<br>&gt; email to <a href="javascript:" target="_blank" \
gdf-obfuscated-mailto="zcYto4xaCgAJ" rel="nofollow" \
onmousedown="this.href=&#39;javascript:&#39;;return true;" \
onclick="this.href=&#39;javascript:&#39;;return \
true;">ossec-list+...@<wbr>googlegroups.com</a>. <br>&gt; For more options, visit <a \
href="https://groups.google.com/d/optout" target="_blank" rel="nofollow" \
onmousedown="this.href=&#39;https://groups.google.com/d/optout&#39;;return true;" \
onclick="this.href=&#39;https://groups.google.com/d/optout&#39;;return \
true;">https://groups.google.com/d/<wbr>optout</a>. <br></blockquote></div>

<p></p>

-- <br />
<br />
--- <br />
You received this message because you are subscribed to the Google Groups \
&quot;ossec-list&quot; group.<br /> To unsubscribe from this group and stop receiving \
emails from it, send an email to <a \
href="mailto:ossec-list+unsubscribe@googlegroups.com">ossec-list+unsubscribe@googlegroups.com</a>.<br \
/> For more options, visit <a \
href="https://groups.google.com/d/optout">https://groups.google.com/d/optout</a>.<br \
/>



[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic