Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hello!I want to konw which files are used to generate alerts in AIT-LDSv1.1 #1

Open
int-man opened this issue Feb 6, 2023 · 1 comment

Comments

@int-man
Copy link

int-man commented Feb 6, 2023

hello!I want to konw which files are used to generate alerts in AIT-LDSv1.1

@landauermax
Copy link
Contributor

Hi! We tried to include as many files as possible; it should be the following list of files:

  • /apache2/-access.log
  • /apache2/-error.log
  • /audit/audit.log
  • /exim4/mainlog
  • /suricata/eve.json
  • /suricata/fast.log
  • /auth.log
  • /daemon.log
  • /syslog'

But not all of them reported alerts when running AMiner and Wazuh/OSSEC on them. If you look at the location field in the alerts generated by Wazuh/OSSEC, you can actually see the name of the input log file. Hope this helps!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants