diff --git a/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml b/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml index f9179432a..87f81605d 100644 --- a/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml +++ b/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml @@ -1,2783 +1,26 @@ - - + - - - - - - - - - - - - - - - - - 1002 - ^pound - Connection timed out - Pound SSL network event ignored - - - - 1002 - ^pound - Connection reset by peer - Pound SSL network event ignored - - - - 1002 - ^pound - e500 error copy client cont to - Pound SSL network event ignored - - - - 1002 - ^pound - error copy chunk cont - Pound SSL network event ignored - - - - 1002 - ^pound - error copy server cont - Pound SSL network event ignored - - - - 1002 - ^pound - /misc/message-24-error.png - Pound SSL network event ignored - - - - 1002,31421 - Call to undefined function - PHP bugs - - - - 1002 - ^drupal - access denied - Access denied to parts of gcl website - - - - 1002 - ^drupal - Internal server error for link - Broken links on GCL via linkchecker module - - - - 1002 - Illegal choice - Message we cannot do anything about - - - - 1002 - ^drupal - XML_ERR_NAME_REQUIRED - Feed problems on enigma6 eiu-research - - - - 1003 - ^drupal - loginticket_login result on fastlogin_init - Very large syslog messages tripping up OSSC on gcl-app1 - - - - 1003 - ^drupal - Call of SugarCRM function - Very large syslog messages tripping up OSSC on gcl-app1 - - - - 1002 - ^drupal - Login attempt (using the "notifications" login ticket - Failed attempt to login to GCL using notifications tickets - - - - 1002 - ^drupal - mollom.getImageCaptcha - Mollom outages - - - - 1002 - ^drupal - All servers unavailable - Mollom outages - - - - 1002 - ^drupal - All servers unreachable or returning errors - Mollom outages - - - - 1002 - ^drupal - mollom.getServerList - Mollom outages - - - - 1002 - ^drupal - Oracle_Project_Failure_Cover - Filename with the word failure - - - - 1003 - ^ovpn-openvpn - PUSH_REPLY - Large OpenVPN syslog message, pushing routes to the user - - - - 1003 - ^drupal - gcl.prod.codeenigma.com:80/sugarcrm - Large SugarCRM messsages - - - - 1003 - ^drupal - www.gamblingcompliance.com/node - Large Drupal watchdog messages - - - - 1003 - ^drupal - www.gamblingcompliance.com/contact - Large Drupal watchdog messages - - - - 1003 - ^drupal - www.gamblingdata.com/contact - Large Drupal watchdog messages - - - - 40101 - ^su - root:nobody - Crons from cron.daily - - - - 1003 - ^drupal - www.gamblingcompliance.com/search/site - Large Drupal watchdog messages - - - - 1003 - ^drupal - Searched Site for - Large Drupal watchdog messages - - - - 1002,1003 - ^drupal - disallowed Unicode code - Unicode errors due to sites that need updating so they work with current PHP versions - - - - 1002 - ^drupal|wcc - Undefined property - PHP warnings and errors - - - - 1002 - ^drupal|wcc - Undefined variable - PHP warnings and errors - - - - 1002,1003 - ^drupal|wcc - Trying to get property of non-object - PHP warnings and errors - - - - 1002 - ^drupal|wcc - to be array, - PHP warnings and errors - - - - 1002 - ^/USR/SBIN/CRON - (CRON) error (grandchild # - Failing crontabs - - - - 1002 - ^ovpn-openvpn - Connection refused - Disconnecting VPN clients - - - - 1002 - ^drupal - Use of undefined constant - PHP bugs in EC sites - - - - 1002,1003 - ^drupal|wcc - Undefined index - PHP bugs in sites - - - - 1002 - ^ovpn-openvpn - TLS Error - Disconnecting VPN clients - - - - 1002 - ^ovpn-openvpn - tls-error - Disconnecting VPN clients - - - - 1002 - ^ovpn-openvpn - Bad LZO decompression header - Disconnecting VPN clients - - - - 1003 - ^drupal - Retrieved new CAPTCHA - Verbose Mollom logging - - - - 1003 - ^drupal - Incorrect CAPTCHA - Verbose Mollom logging - - - - 1003 - rest.mollom.com - Mollom messages are often too verbose and trip OSSEC on 1003 - - - - 1002 - Finished processing scheduled jobs - Job Scheduler in Drupal uses the word 'failed' even when 100% success. Ignore - - - - 1002 - Preventing ms_DRBD_NFS from re-starting on - monitors can't run resources - - - - 1002 - ^nslcd - request denied by validnames option - Jenkins Duplicity jobs trigger nslcd verbose message - - - - 1002 - ^php - No buffer to delete in /usr/share/php/pearcmd.php on line 19 - Ignore buggy pearcmd.php on PHP 5.4 - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - failed with code - Buggy feed app - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - Apache Solr - Solr comm fail - - - - 1003 - airmic-app2.codeenigma.net - ^drupal - IDS Detector Details - airmic civicrm - - - - 1003 - airmic-app2.codeenigma.net - ^drupal - apachesolr_search - airmic solr - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - oauth_consumer_key - airmic mollom - - - - 1002 - ^nagios3 - SOLR Cores - Ignore automatic SOLR alerts on midnight - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - The page you requested is currently unavailable - civicrm - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - Terrorism - civicrm - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - DB Error: already exists - civicrm - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - Could not find valid value for id - civicrm - - - - 1003 - airmic-app2.codeenigma.net - ^drupal - backTrace - civicrm - - - - 1003 - airmic-app2.codeenigma.net - ^drupal - civicrm - Airmic CiviCRM - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - We can't load the requested web page - Airmic CiviCRM - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - You do not have permission to access this page - Airmic CiviCRM - - - - 1003 - airmic-app2.codeenigma.net - ^drupal - has answered your question - Airmic CiviCRM - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - ERROR_CONTACT - Airmic CiviCRM - - - - 1002 - ^nslcd - Can't contact LDAP server - Occasional connection closures on LDAP lookups from remote locations - - - - 1002 - ^rngd - FIPS 140-2 failures - rngd-tools - - - - 1002,1003 - ^drupal|wcc - Invalid argument supplied for foreach - Bug in site - - - - 1002 - wt-stage2.codeenigma.net - ^drupal - SearchApiSolrConnection - Badly configured Solr - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - Solr - Badly configured Solr - - - - 1002 - ^drupal - seems to be broken - Bad feeds - - - - 1003 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - ^drupal - swf.swf - Bad URL - - - - 1002 - wt-app3.codeenigma.com|wt-app4.codeenigma.net - ^drupal - SearchApiSolrConnection - Bad Solr config - - - - DatabaseConnection->escapeLike - SQL attempt in form - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - failed with code 410 - Bad twitter feed - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - foreach - Bad code - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - ^drupal - aspxerrorpath - Bad URL - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - stat failed - Missing files - - - - 1002 - redactive-dev2.codeenigma.net - ^drupal - SearchApiException while optimizing Solr server - Missing solr - - - - 1002 - ^drupal - seems to be broken - Bad feeds - - - - 1002 - ^drupal - Bad RequestApache - Bad solr - - - - 1002,1003 - terror|error.asp - The word terror is not considered a hacking attack - - - - 1002 - bad|attack - These words are harmless - - - - 1002 - ^systemd - Failed to read PID from file - Harmless bug - - - - 1002 - swift-app1.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app6.codeenigma.net - Compilation failed - Harmless bug - - - - 1002 - monitor3.codeenigma.net|monitor2.codeenigma.com - ^nagios3 - SERVICE - Noisy Nagios will alert us itself if there is a real problem - - - - 1002 - ^kernel - floppy: error -5 while reading block 0 - Noise - - - - 1002 - ^systemd - Failed to reset devices.list on /system.slice - Noise - - - - 1002 - ^drupal - check the manual that corresponds to your MySQL server version for the right syntax to use near - Buggy code - - - - 1002 - ^drupal|cricknet - Connection refused in SearchApiSolrConnection - Ignore harmless solr error - - - - 1002 - monitor3.codeenigma.net - ^ntop - rrd_update - Ignore nTop messages - - - - 1002 - Illegal string offset - Noisy PHP bug - - - - 1002,1003 - wt-stage2.codeenigma.net - ^drupal - 401 Unauthorized - Noisy stage sites - - - - 1002 - monitor3.codeenigma.net - ^ovpn-openvpn - AUTH_FAILED|TLS Auth Error|PLUGIN_AUTH_USER_PASS_VERIFY failed|SSL3_GET_CLIENT_CERTIFICATE - Failed attempt to login to OpenVPN - - - - 1002 - ^drupal - Error sending e-mail - failed email send - - - - 1002 - jenkins2.codeenigma.net - ^openvpn - fail - Ignore failing VPN - - - - 1002 - monitor3.codeenigma.net - ^ovpn-openvpn - bad packet ID - Flaky OpenVPN clients - - - - 1002 - ^drupal - The file upload failed - Buggy client code or some other app issue - - - - 1003 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - mapping-ISOLatin1Accent.txt - Solr noise - - - - 1002 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - Internal Server Error: Internal Server Error in apachesolr_cron - Solr noise - - - - 1002 - Feed processing failed - App noise - - - - - 1002 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - The configuration file {/var/www/piwik/config/config.ini.php} has not been found or could not be read - Piwik not installed - - - - 1002 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - An unexpected website was found in the request - Piwik fail - - - - 1003 - ^drupal - Reacting on event - Large syslog messages on aps - - - - 1002 - nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net - Connection refused - Solr error - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net|wt-stage2.codeenigma.net - ^drupal - Invalid view mode - Bad code - - - - 1002 - ^freshclam - Can't find or parse configuration file /etc/clamav/clamd.conf - Jessie upgrade - - - - 1003 - nycc-dev2.codeenigma.net|nycc-app3.codeenigma.net - unknown field - Noisy syslog message - - - - 1002 - nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net - Name or service not known - Noisy syslog message - - - - 1002 - nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net - A fast 404 test - Noisy syslog message - - - - 1002 - /usr/bin/filebeat - SSL client failed to connect - Ignore noisy disconnections - - - - 31421 - wt-stage2.codeenigma.net - planer_three_region.inc - Ignore noisy bug on WT stage - - - - 1002 - freshclam - Can't download - Ignore clamav outage - - - - 1002 - freshclam - Connection refused - Ignore clamav outage - - - - 1002 - drupal - redactive-app3.codeenigma.net - Undefined offset - Ignore buggy code - - - - 1002 - monitor3.codeenigma.net|monitor2.codeenigma.com - ^nagios3 - API returned error - Buggy Pingdom or Statuscake - - - - 1002 - wt-stage2.codeenigma.net|wt-app3.codeenigma.net|wt-app4.codeenigma.net - ^drupal - Can't contact LDAP server - Ignore LDAP alerts in Drupal - - - - 1002,1003 - Illegal offset type - Buggy code - - - - 1003 - airmic-app2.codeenigma.net - cron running apachesolr_nodeapi_mass_delete - Harmless message - - - - 1002,1003 - Data too long for column - Noisy MySQL exception - - - - 1002,1003 - wt-stage2.codeenigma.net - swf.swf - More awful coding by apparent professionals - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - TotalRequests Limit exceeded - salesforce issue - - - - 3330 - ^postfix - 451 Internal resource temporarily unavailable - greylisting - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - is not of the type Positive - civicrm issue - - - - 1002 - ^drupal - bytes in _dmemcache_get_pieces() - Bug in memcache module in distributed setups - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - failed to load destination URL - ads issue - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - ^drupal - error404 - false positive - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - chain - false positive - - - - 1003 - ^drupal - nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net - .asp - Bot noise - - - - 1002 - ^varnishd - VCL_MET_BACKEND_ERROR - Normal Varnish reload - - - - 1002 - ^varnishd - backend_error - Normal Varnish reload - - - - 1002 - ^varnishd - synth+error - Normal Varnish reload - - - - 1002 - ^varnishd - Return error code 405 - Normal Varnish reload - - - - 1002 - ^varnishd - h1 - Normal Varnish reload - - - - 1002 - ^varnishd - invisibly - Normal Varnish reload - - - - 1002,1003 - ^drupal - Missing bundle property on entity of type - Buggy site - - - - drupal - php module enabled - PHP module has been enabled on this Drupal site - - - - 1002,1003 - ^drupal - Data truncated for column - Buggy site - - - - 1003 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - ^drupal - EntityStructureWrapper - Buggy site - - - - 1003 - swift-app1.codeenigma.net - ^drupal - doubleclick - False positive - - - - 1002 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app6.codeenigma.net - ^drupal - from no-reply@stem.org.uk|Failed sending email - Bad mail attempts - - - - 1002 - govwales-app3.codeenigma.net|govwales-app4.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - Request failed: Connection refused - Bad solr - - - - 1002,1003 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - ^drupal - field_organisation_target_id - Buggy site - - - - 1003 - swift-app1.codeenigma.net - ^drupal - flashtalking - Big referer - - - - 1002 - ^drupal|wcc - as the parent data structure is not set - Buggy site - - - - 1002 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - ^snmpd - get_errorcounters - SNMP message - - - - 1002,1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - Recieved - Varnish noise - - - - 1002,1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - Authentication to server failed - Varnish noise - - - - 1002,1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - Socket error - Varnish noise - - - - 40111 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^varnishd - CLI Authentication failure from telnet - Varnish noise - - - - 1002,1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - Request failed - Varnish noise - - - - 1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - CLI telnet - Varnish noise - - - - 1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - Expiration was executed - Varnish noise - - - - 1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - Rd ban req.http.host - Varnish noise - - - - 1002 - ^drupal - Unable to render media - Buggy site - - - - 31412,31421,1002 - airmic-app2.codeenigma.net - adserve.inc on line 274 - Buggy site - - - - 1003 - ^varnishd - CLI telnet 127.0.0.1 - Varnish noise - - - - 1002 - redactive-app3.codeenigma.com - ^drupal - Unexpected error the MTL API - 3rd party service down - - - - 1002 - puppet3.codeenigma.net - failedbackupscheck - Harmless script name - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - 500-unexpected-error-occured - Noisy 404s - - - - 1002 - ^dockerd - be forced - Noisy docker cleanup - - - - 1002 - monitor3.codeenigma.net|monitor2.codeenigma.com - ^nagios3 - A TLS packet with unexpected length was received - Flaky network - - - - 1002 - monitor3.codeenigma.net|monitor2.codeenigma.com - ^nagios3 - Empty reply from server - Flaky network - - - - 1002 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - ^drupal - failed to open file handle - Buggy code - - - - 1003 - swift-app1.codeenigma.net - ^drupal-exacom - exa_rules - Noisy code - - - - 1002,1003 - swift-app1.codeenigma.net - ^drupal - Attempting to re-run cron while it is already running - cron collision - - - - 1002 - ^sshd - no matching cipher found - crawler - - - - 1002 - monitor3.codeenigma.net|monitor2.codeenigma.com - ^nagios3 - Was both Username and API Key provided - crawler - - - - 1002 - airmic-app2.codeenigma.net - ^drupal - PEAR_ErrorStack::singleton - deprecated code - - - - 1002,1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ^drupal - rbipdebug - debug code - - - - 1002 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - __clone method called on non-object in - buggy code - - - - 1002,1003 - wt-stage2.codeenigma.net - ^drupal - SearchApiException while - buggy code - - - - 1002,1003 - airmic-app2.codeenigma.net - ^simplesamlphp - Use of undefined constant AIRMIC_SIMPLESAMLPHP_SAML20_IDP_REMOTE - buggy code - - - - 1002,1003 - airmic-app2.codeenigma.net|hlt-app1.codeenigma.net|rcpch-dev2.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - ^simplesamlphp|SimpleSAMLphp - Error|Headers|errors - buggy code - - - - 1002 - The following module is missing from the file system - Noisy code - - - - 1002,1003 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - ^drupal - METADATANOTFOUND - buggy code - - - - 1003 - no_email_alert - Silence the 1003 alerts - - - - 1002 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - Broken pipe in _clamav_scan_via_daemon - Not a security issue - - - - 1002 - ^drupal|wcc - SMTP error: Could not authenticate - Not a security issue - - - - 1002 - swift-app1.codeenigma.net - ^drupal|wcc - Lost connection to MySQL server during query - MySQL crash or slow queries need optimising - - - - 1002 - wt-stage2.codeenigma.net - ^drupal - Revert - False positive - - - - 31421 - ^php - Call to undefined function apc_clear_cache - False positive - - - - 1002 - Failed opening - Buggy code - - - - 1002 - ^drupal - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - occurred when trying to fetch - stage_file_proxy error - - - - 1002 - ^dnsmasq - monitor3.codeenigma.net - Operation not permitted - caused by someone in the VPN - - - - 1002 - ^drupal - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - Error fetching data from - 3rd party service - - - - 1002 - ^drupal - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - Unknown error - Noise - - - - 1002 - airmic-app2.codeenigma.net - link.vars.php - Noise - - - - 1002 - ^drupal - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - Connection refused - Noise - - - - 1002 - airmic-app2.codeenigma.net - Duplicate entry - Noise - - - - 1002 - ^drupal - redactive-dev2.codeenigma.net - Connection refused - Noise - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - Do_not_worry_about_it - Noise - - - - 1002 - ^rrdcached - monitor3.codeenigma.net - found extra data on update argument - Bug in rrdcached - - - - 1002 - ^rrdcached - monitor3.codeenigma.net - failed with status - Bug in rrdcached - - - - 1002 - nycc-app3.codeenigma.net - libssh2.so - php bug - - - - 1002 - ^drupal - myscience-dev3.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net - API call to - Ignore Stem API errors - - - - 1002 - ^drupal - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net - User account creation error - Ignore Stem API errors - - - - 1002 - ^drupal - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net - Wrong return data for - Ignore Stem API errors - - - - 1002,1003 - ^drupal - myscience-dev3.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net - Base table or view not found - Ignore Stem errors - - - - 1002,1003 - ^drupal - myscience-dev3.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net - Error creating/updating Achiever contact - Ignore Stem errors - - - - 1002 - hlt-app1.codeenigma.net - Validation with key - Ignore SimpleSAML errors - - - - 1002 - airmic-app2.codeenigma.net - Cannot redeclare class - PHP site bug - - - - 1002 - redactive-app3.codeenigma.net - Error opening socket - false positives - - - - 1002 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - Login denied from - noisy alert - - - - drupal - Potentially unsafe keys - Potentially unsafe keys found in request parameters - - - - 1002 - AcquiaSearchService - Noisy solr bug - - - - 1002 - govwales-ldn-dev2.codeenigma.net - doc.rtl - Noisy site bug - - - - 1002 - ^drupal - Unknown error - Drupal noise - - - - 1002 - ^CRON - Cron error - Epiqo cronjob noise - - - - 1002 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net|govwales-ldn-app6.codeenigma.net - The resource owner or authorization server denied the request - Noisy - - - - 1002 - SimpleSAML_Error|NOSTATE|UNHANDLEDEXCEPTION - Noise - - - - 1002 - ^drupal - HTTPRedirect - Noise - - - - 1002,1003 - Headers already sent - buggy code - - - - 1002 - access-denied|ShowErrors|failedattempt|User_error|AH00036|AH02032|display_errors|valid-user|RequireAny|FailedURI|user_refused|i2cerrors|aspxerrorpath|No such file or directory|trial-and-error|AH01991|AH00687|Failure.ppt|advagg|fatal-fire|failure.jpg|on_error|judging-our-errors|20fail|locationError|permissiondenied|AH01996|SSL23_GET_CLIENT_HELLO|supermarket-refused|moodle_exception|ERROR_CONTACT_SUPPRESSED|failed=1|_refused|errors-|error-404|error_|-error|98failure|error.png|fatale|_error - normal 403s - - - - 1002,1003 - fci-dev2.codeenigma.net - ^cricknet - Unable to get a data value - buggy code - - - - 1002 - ^ovpn - TLS key negotiation failed|TLS handshake failed - port-scanning VPN servers is noisy - - - - 1002 - ^drupal - wt-app3.codeenigma.net|wt-app4.codeenigma.net - Failed to push json to s3 - Site bug - - - - 1002 - ^drupal - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app4.codeenigma.net - Call to a member function getCompanyNo - Noisy site bug - - - - 1002 - ^cron-nsfailover - Operation not permitted - Noisy stretch alert - - - - 1002 - ^agent - jmxfetch - Noisy alert - - - - 1002 - ^drupal - Queue size - Noisy Drupal alert - - - - 1002 - ^puppet-agent - Composer - Noisy Puppet alert - - - - 1002 - ^dockerd - cgroup path for memory not found - Noisy Docker alert - - - - 1002 - ^puppet-agent - ffaker - Noisy alert - - - - 1002 - myscience-dev3.codeenigma.net|myscience-dev4.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app5.codeenigma.net|myscience-app6.codeenigma.net - Argument 1 passed to - Noisy alert - - - - 1002 - ^drupal - Could not connect to Mailchimp - Noisy alert - - - - 5501,5502 - git2.codeenigma.net|jenkins2.codeenigma.net|iaea-utilities2.codeenigma.net|govwales-utility2.codeenigma.net|nycc-utility2.codeenigma.net|myscience-utility1.codeenigma.net|airmic-utility2.codeenigma.net - ^sshd - for user git - Noisy alert - - - - 5715 - git2.codeenigma.net|jenkins2.codeenigma.net|iaea-utilities2.codeenigma.net|govwales-utility2.codeenigma.net|nycc-utility2.codeenigma.net|myscience-utility1.codeenigma.net|airmic-utility2.codeenigma.net - ^sshd - Accepted publickey for git - Noisy alert - - - - 1002,1003 - govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net - ShieldMiddleware - Noisy alert - - - - 1002 - myscience-dev3.codeenigma.net|myscience-dev4.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app5.codeenigma.net|myscience-app6.codeenigma.net - Problem processing JSON - Noisy alert - - - - 1002 - ^awslogs - is not running - Noisy alert - - - - 1002 - ^amazon-ssm-agent - AccessDeniedException|Failed|error - Noisy alert - - - - - - - - - - drupal - Drupal - Drupal syslog message - - - - 104110,1002 - Login attempt failed - Drupal failed login! - - - - 104120 - - Login attempt failed for admin. - Drupal failed attempt to log in as admin! - - - - 104120 - Possible Drupal brute force attack - (high number of logins). - - - - - 104110 - Illegal choice - Drupal possible input injection (XSS/XSRF) attack! - - - - 104110,1002 - Access denied - Drupal access denied error (permissions rejected). - - - - 104150 - admin/ - Drupal access denied to admin screen. - - - - - - - - - - 31122 - GET /sites/default/files/styles - Unable to generate derived image in Drupal - ignored - - - - 1002 - markets-and-market-failure - False positive due to name of URL - - - - 31151 - iepngfix.htc - Missing image on thorogood site - - - - 31151,31115 - flashtalking/ftlocal.html - Broken ads on revisionworld.co.uk - - - - 31122 - POST /node/add/study_calendar - Broken app on revisionworld.co.uk - - - - 31151 - Preloader10.swf - Broken app on revisionworld.co.uk - - - - 31151,31115 - DARTIframe - Broken app on revisionworld.co.uk - - - - 31151 - wmode=transparent - Broken app on revisionworld.co.uk - - - - 1003 - GET /production/catalog - Puppet check-ins create a large syslog message, ignore it - - - - 1003 - GET /stage/catalog - Puppet check-ins create a large syslog message, ignore it - - - - 1003 - GET /dev/catalog - Puppet check-ins create a large syslog message, ignore it - - - - 31122 - 500 5 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) - Googlebot 500 errors (on GCL site) - - - - 1002 - LookupIdVisitor - EC Asia errors seen in nginx log - - - - 1003 - GET /issues/context_menu - Large redmine apache access logs - - - - 1003 - GET /projects/gcl - Large redmine apache access logs - - - - 31151 - FlipboardProxy - FlipboardProxy logs 499 error code particularly on GCL - - - - 31153 - trusted-sources - googlebot going bananas on paginated parts of the variantperception site - - - - 31151 - atlas_js_shared.js - Missing javascript file triggering 404 active response - - - - 31122 - GET /en/sites/default/files/styles - imagecache from bots on codeenigma site - - - - 31122 - GET /fr/sites/default/files/styles - imagecache from bots on codeenigma site - - - - 31122 - "POST /user/register HTTP/1.1" 500 5 "http://www.gambling - bots on GCL site - - - - 31152 - enigma3.codeenigma.net - web-accesslog - photos-for-sale - Strange Thorogood URLs interpreted as SQL injection attacks - - - - 31123 - /var/log/nginx/access-support.prod.log - web-accesslog - "GET / HTTP/1.1" 503 - Googlebot hitting a site that is offline - - - - 31123 - /var/log/nginx/access-the-planner.prod.log - web-accesslog - HTTP/1.1" 503 - Site is in maintenance mode - - - - 31122 - /var/log/nginx/access-spring.log - web-accesslog - 500 - Internal server error on this site - - - - 31151 - web-accesslog - GET /sites/default/files/styles - Common location for 403 or 401 codes on Drupal imagecache - - - - 31122 - web-accesslog - ++++++++++++++++++++++++++++Result - Spambots - - - - 31151 - web-accesslog - /var/log/nginx/access-sm.prod.log - feed - RSS crawling bot - no_email_alert - - - - - - 31151 - web-accesslog - /var/log/nginx/access-sm.prod.log - getresource.axd - Broken ad 404ing probably trips OSSEC and user access - - - - 31151 - web-accesslog - /var/log/nginx/access-airmic.prod.log - CRM_Contact_Page - Client doing something with ajax in civicrm that throws spurious 499 codes - - - - 31151 - web-accesslog - /var/log/nginx/access-airmic.prod.log - boost-gzip-cookie-test.html - Client doing something with ajax in civicrm that throws spurious 499 codes - - - - 31151 - /var/log/apache2/access-tcs-intranet.log - itok - Requesting various assets seems to result in a 403 at least temporarily, trips OSSEC and likely blocks users - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - admanmedia - Residual 404s on WT due to re-used IP on loadbalancer from a previous customer - - - - 31151 - /var/log/nginx/access-bigpicture.prod.log - eot - 404s on Big Picture site - - - - 31151 - /var/log/nginx/access-bigpicture.prod.log - fast_facts/json/all - 403s on Big Picture site - - - - 31101 - Microsoft Office Protocol Discovery - Probably an OPTIONS request from Microsoft Office Protocol Discovery user-agent - - - - 31151 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - admanmedia - Residual 404s on WT due to re-used IP on loadbalancer from a previous customer - - - - 31153 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - admanmedia - Residual 404s on WT due to re-used IP on loadbalancer from a previous customer - - - - 31122 - /var/log/nginx/access-sm.prod.log - HTTP/1.1" 500 - 500s on Supply Management site - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - message-24-error.png - harmless jpeg - - - - 31151 - /var/log/nginx/access.org.log|/var/log/nginx/access-actionaid.org.log - aaidonazione/confirmDonation.do?codeTransaction - 404s every 30 min or so on ActionAid from Italy to some donation page - - - - 31151 - OPTIONS /system - Microsoft silliness - - - - 31151,31122 - PROPFIND /system - Microsoft silliness - - - - 31151 - chsoc-app2.codeenigma.net - /user/login/sso - SSO component on CHSOC sites - - - - 31151 - chsoc-app2.codeenigma.net - OPTIONS - Misbehaving browsers on chsoc - - - - 1002 - Method has been changed to GET - Ignore broken links in linkchecker module reporting to watchdog - - - - 31101 - web-accesslog - /bin/bash - Shellshock attempt - - - - 31101 - redactive-app3.codeenigma.net - web-accesslog - bkg-header.png - 404s - - - - 31101 - /var/log/nginx/access-ecg.log - web-accesslog - medmastery.com - 403s - - - - 31101 - /var/log/nginx/access-ecg.log - web-accesslog - course - 403s - - - - 1003 - gclid - Ignore large weblog with big Referer (google ad?) - - - - 31101 - redactive-app3.codeenigma.net - web-accesslog - GET /news-feed.rss - ignore 404 - - - - 31101 - redactive-app3.codeenigma.net - web-accesslog - GET /newsrss.rss - ignore 404 - - - - 31530,31108 - ] "POST \S+.php\.+HTTP/1.\." 200 - POST request to a file ending in .php extension - - - - 31530,31108 - ] "POST \S+.html - POST request to a file ending in .html extension - no_email_alert - - - - 31122 - redactive-app3.codeenigma.net - \\x - 500 errors with strange characters in the URLs, seems to recur on occasion - - - - 101100,1002 - jstats|kibana|geocoding - Stats - - - - 101100 - statistics.php - Stats - - - - 101100 - wp-admin - Normal Wordpress activity - - - - 31101 - redactive-app3.codeenigma.net - web-accesslog - 85.232.51.149 - GET /opinion/header - 404s - - - - 31122,1002 - /var/log/nginx/access-mapmeo.log|/var/log/nginx/access-www.meinestelle.de.log|/var/log/nginx/access-empla.log|/var/log/nginx/access-unicum.log - hybridauth - Broken Epiqo app - - - - 1002,1003,31123 - terror|bad|attack|error.asp|errordetail1|Error.aspx|error.svg|planning-error|failures|error500|failed_uli|channelling-failure|Error%20|-failure|-failed|-illegal|search-error|failure- - The word terror is not considered a hacking attack - - - - 101100 - redactive-app3.codeenigma.net|redactive-dev2.codeenigma.net - emit.php - Stats - - - - 31101 - redactive-dev2.codeenigma.net|redactive-app3.codeenigma.net - web-accesslog - feed - ignore 404 - - - - 30101 - /var/log/apache2/error.log - server reached MaxClients setting, consider raising the MaxClients setting - MaxClients threshold reached - - - - 31122 - /var/log/nginx/access-revisionworld.log - Buggy revisionworld - - - - /var/log/nginx/access-scambs-drupal.prod.log - POST /user - no_email_alert - Ignore user post - - - - 101131 - Possible Drupal brute force attack - (high number of requests to /user). - no_email_alert - - - - 1002 - /var/log/nginx/access-actionaid.org.log - abad|ebad - Ignore URL - - - - 101100 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - machform - Machform is OK to POST to - - - - 31122 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - piwik.php - Piwik broken or not installed - - - - 1003 - search.yahoo.com - Big referer - - - - 101055 - OPTIONS - OPTIONS request from Microsoft Office Protocol Discovery user-agent - - - - 101100 - airmic-app2.codeenigma.net|enigma3.codeenigma.net - xmlrpc - POST to apparently OK script - - - - 1003 - jsredir - Noisy Yandex - - - - 1002 - /misc/message-24-error.png - false positive word - - - - 31533 - POST /batch? - Normal to see high rate of POSTs to batch pages in Drupal - - - - 31122 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - mwt_republish/nojs - Buggy code - - - - 31151 - /var/log/nginx/access-corporate.prod.log - Ignore 404s on newly launched site for now - - - - 101100 - jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net - limesurvey - Normal POST request - - - - 1002 - /var/log/apache2/error-iaea.master.log - from remote server - Bugs with IAEA remote legacy app - - - - 1003 - /var/log/nginx/access-unitedway.log - job_geo_location - Large nginx log messages - - - - 31161 - swift-app1.codeenigma.net - sites/revisionworld.com/files - Deliberate 501 code on revisionworld.com - - - - 1002 - wt-app3.codeenigma.net|wt-app4.codeenigma.net - mwt-republish-img - Noisy referer - - - - 31533 - /var/log/nginx/access-stem.prod.log - js/shs/json - Normal high rate of POSTs to Stem site - - - - 31122 - /var/log/nginx/access-stem.prod.log - system/ajax - Buggy site - - - - 101100 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - ^drupal - idp - Big IDP request - - - - 1002,1003 - redactive-dev2.codeenigma.net - ^drupal - 401 Unauthorized - Noisy stage sites - - - - 31151,31101 - /var/log/nginx/access-smartsolutions.prod.log - Ignore 40X in logs on nycc-app1 smartsolution site, there are too many 401s/404s due to site rebuild - - - - 101100 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - drupalauth - SAML auth - - - - 31151,31152,31153,31154 - OpenVAS - 127.0.0.1 - no_email_alert - Too noisy - - - - 1003 - myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net - SSOService.php - SAML auth - - - - 1002 - /var/log/nginx/access-govwalesd7.master.log - care-and-support-business-failure-wales-regulations-2015-and-care-and-support - False positive - - - - 1002 - /var/log/nginx/access-sono.log - abdominal - False positive - - - - 31533 - /var/log/nginx/access-bookworks.log - publishing - Frequent high rate of POSTs - - - - 31122 - /var/log/nginx/access-hosting-dashboard.prod.log - StatusCake - bad deploy - - - - 31123 - /var/log/nginx/access-ai.prod.log|/var/log/apache2/access-cwh.prod.log - web-accesslog - maint mode - - - - 31123 - /var/log/nginx/access-stem.amb_dev.log - web-accesslog - maint mode - - - - 31101,31151 - web-accesslog - /var/log/nginx/access-recruiter.prod.log - rss - RSS crawling bot - no_email_alert - - - - 31101,31151 - web-accesslog - /var/log/nginx/access-recruiter.prod.log - national-news.xml - RSS crawling bot - no_email_alert - - - - 31101,31151 - web-accesslog - /var/log/nginx/access-thorogood.prod.log - leaflet - Buggy - - - - 31122 - web-accesslog - /var/log/apache2/access-festival_micro.prod.log - Buggy - - - - 31101,31151 - web-accesslog - /var/log/nginx/access-wcc.ce-prod.log - panels|planning|guide - Buggy - - - - 31122 - web-accesslog - /var/log/nginx/access-bookworks.log - imagecache - Meh - - - - 31533 - /var/log/nginx/access-rcm.prod.log - POST /cas/login - Normal to see high rate of POSTs to /cas/login pages - - - - 31122 - /var/log/nginx/access-hosting-dashboard.prod.log - favicon.png - Buggy code - - - - 31533 - /var/log/nginx/access-stem.prod.log - POST /plupload-handle-uploads - Normal to see high rate of POSTs to /plupload-handle-uploads pages - - - - 31123 - /var/log/nginx/access-hav-j150709.prod.log|/var/log/nginx/access-pri-j150281.prod.log - web-accesslog - site offline - - - - 1002 - /var/log/nginx/access-the-planner.prod.log - failure|error|refused|denied|illegal - false positive - - - - 1002 - message-16-error.png - false positive in omega theme - - - - 1002,31122 - /var/log/nginx/access-mapmeo.log - jserror - false positive - - - - 31122 - /var/log/apache2/access-cwh.prod.log - major-works - site bug - - - - 101100 - enigma3.codeenigma.net - wp-cron.php - Wordpress - - - - 31151 - Jorgee - no_email_alert - Noisy scanner - - - - 31122,1002 - /var/log/nginx/access-unicum.log - inhalt - False positive - - - - 31122,1002 - /var/log/nginx/access-platform-prod.log - api - Noise I cannot do anything about - - - - 31122,1002 - /var/log/nginx/access-rcm.prod.log - print|news-views-and-analysis|rss - Noise I cannot do anything about - - - - 31122,1002 - /var/log/nginx/access-platform-prod.log - platform - Noise I cannot do anything about - - - - 31151,31101 - /var/log/nginx/access-platform-prod.log - Ignore 40X on STEM platform - - - - 31123 - /var/log/nginx/access-actionaid.org.log|/var/log/nginx/access.org.log - Ignore 503s on AAI (bots being rate-limited) - - - - 31122,1002 - /var/log/nginx/access-ecgstage.log - chargebee - bug on ECG stage site - - - - 1002 - /var/log/nginx/access-govwalesd8.master.log - common-errors - false positive - - - - 1002 - /var/log/nginx/access-cambridge.gov.uk.prod.log - BuildFailureDetector - False positive - - - - 31108,31101 - 23value|23default_value|23markup|element_parents=%23 - web-accesslog - RCE attempt maybe - no_email_alert - - - - 31122 - /var/log/apache2/access-rcm.prod.log - rss.xml - Site bug - - - - 31122 - myscience-dev4.codeenigma.net - Site bug - - - - 31122 - /var/log/nginx/access-jpoesen.com.log - web-accesslog - comment/reply - Internal server error on this site - - - - 31122 - /var/log/apache2/access-iaea.master.log|/var/log/apache2/access-iaea.drupal-direct.log - Buggy site - - - - 1002 - client denied by server configuration - 403d response - no_email_alert - - - - 1002 - 2fa.codeenigma.net - wsgi:error - Bugs in LinOTP - - - - 31530 - /var/log/nginx/access-corporate.prod.log - general-enquiry - Possible spamming of WT corporate contact form - - - - - 1002 - access-denied|ShowErrors|failedattempt|User_error|AH00036|AH02032|display_errors|valid-user|RequireAny|FailedURI|user_refused|i2cerrors|aspxerrorpath|No such file or directory|trial-and-error|AH01991|AH00687|AH01276|Failure.ppt|advagg|fatal-fire|failure.jpg|on_error|judging-our-errors|20fail|locationError|permissiondenied|AH01996|SSL23_GET_CLIENT_HELLO|supermarket-refused|moodle_exception|ERROR_CONTACT_SUPPRESSED|failed=1|_refused|errors-|error-404|error_|-error|98failure|error.png|fatale|_error - normal 403s - - - - /var/log/apache2/access-cwh.prod.log - Ignore 404s on cwh for now to avoid blocking users being proxied from HAproxy - - - - /var/log/apache2/access-wcc.ce-prod.log - 31101,31151,1002 - fa-solid-900 - Ignore missing font files on new WCC site - - - - 101100 - /var/log/nginx/access-wcc.ce-prod.log|/var/log/nginx/access-johnthorogood.prod.log - wp-login.php - False positive - - - - 31101,31151,1002 - /var/log/nginx/access-tephinet.master.log|/var/log/nginx/access-tephinet.staging.log - GET /sites/tephinet/files/styles - Ignore missing style files on Mantaray Tephinet site - - - - 31151,31101 - wt-stage2.codeenigma.net - Ignore 40X in logs on wt-stage2, there are too many 401s/404s due to misbehaving apps - - - - - - - - - 31120 - ^502 - Web server 502 error code (Bad gateway). - - - - 31124 - /var/log/nginx/access-actelion.log - web-accesslog - Ignore 502s that we can't be responsible for (legacy sites) - - - - 31123 - /var/log/nginx/access-nycc.prod.log - Strange 503s - - - - - - - 521 - scantem - Whitelist alerts containing 'scantem' in the title. - no_full_log - - - + + + + + + + 5716 + 1.1.1.1 + sshd: authentication failed from IP 1.1.1.1. + authentication_failed,pci_dss_10.2.4,pci_dss_10.2.5, + + + + + + 521 + scantem + Whitelist alerts containing 'scantem' in the title. + no_full_log + + + +