Bug #343
OSSEC-HIDS 1.6.1 always sets assessment.impact.completion = succeded
Status:
New
Priority:
Normal
Assignee:
-
Category:
Sensor development/review
Target version:
-
Start date:
Due date:
% Done:
0%
Resolution:
Description
Example: the IDMEF alerts for both of these logs
[[WinEvtLog]]: Security: AUDIT_SUCCESS(673): Security: SYSTEM: NT AUTHORITY: SERVER: user@DOMAIN DOMAIN PC$ %{SOMERANDOMUIDHERE} 0x40810010 0x17 10.10.10.10 - {SOMEOTHERUID} - [[WinEvtLog]]: Security: AUDIT_FAILURE(673): Security: SYSTEM: NT AUTHORITY: SERVER: - 0x2 - 10.10.10.10 0x20 - -
have assessment.impact.completion = succeeded
History
#1 Updated by Antoine LUONG over 7 years ago
- Description updated (diff)
- Assignee deleted (
Sebastien Tricaud)