Giter Site home page Giter Site logo

ta-linux_secure's People

Contributors

doksu avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar

ta-linux_secure's Issues

vendor_action Extraction

Hi

Thanks for the TA.
I have 2 kinds of logs in which the vendor_action is not contained in linux_secure_vendor_actions.csv.

Here is a sample for the 2 values I get as vendor_actions:

vendor_action=-f
May 18 11:09:42 XXXX sshd[2780]: Starting session: forced-command (config) 'internal-sftp -l VERBOSE -f AUTHPRIV' for XXXX from XX.XXX.XX.XX port 36896 id 0 [postauth]

vendor_action=-session:
May 18 11:03:03 XXXX sshd[34568]: Starting session: command for grid from XXX.XXX.XX.XXX port 34791 id 0

version = 1.0.0

Cheers

Marta

SRC_IP Extraction for SSH Logins.

Hi

Thanks for the TA. I am finding it is not extraction SRC_IP although specified in this stanza.

[sshd_auth]
REGEX = (\S+) (\S+) for (\S+) from (\S+) port (\d+) ([^\:]+)(?:: (\S+) (\S+))?
FORMAT = vendor_action::$1 auth_method::$2 user::$3 src_ip::$4 src_port::$5 ssh_protocol::$6 algorithm::$7 public_key_fingerprint::$8

Regex is valid but not working. Il seek to resolve but just for tracking.

Version 0.1.3.

Cheers,

Paul

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.