diff --git a/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml b/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml
index f9179432a..87f81605d 100644
--- a/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml
+++ b/roles/debian/wazuh/templates/var-ossec-rules-local_rules.xml
@@ -1,2783 +1,26 @@
-
-
+
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
- 1002
- ^pound
- Connection timed out
- Pound SSL network event ignored
-
-
-
- 1002
- ^pound
- Connection reset by peer
- Pound SSL network event ignored
-
-
-
- 1002
- ^pound
- e500 error copy client cont to
- Pound SSL network event ignored
-
-
-
- 1002
- ^pound
- error copy chunk cont
- Pound SSL network event ignored
-
-
-
- 1002
- ^pound
- error copy server cont
- Pound SSL network event ignored
-
-
-
- 1002
- ^pound
- /misc/message-24-error.png
- Pound SSL network event ignored
-
-
-
- 1002,31421
- Call to undefined function
- PHP bugs
-
-
-
- 1002
- ^drupal
- access denied
- Access denied to parts of gcl website
-
-
-
- 1002
- ^drupal
- Internal server error for link
- Broken links on GCL via linkchecker module
-
-
-
- 1002
- Illegal choice
- Message we cannot do anything about
-
-
-
- 1002
- ^drupal
- XML_ERR_NAME_REQUIRED
- Feed problems on enigma6 eiu-research
-
-
-
- 1003
- ^drupal
- loginticket_login result on fastlogin_init
- Very large syslog messages tripping up OSSC on gcl-app1
-
-
-
- 1003
- ^drupal
- Call of SugarCRM function
- Very large syslog messages tripping up OSSC on gcl-app1
-
-
-
- 1002
- ^drupal
- Login attempt (using the "notifications" login ticket
- Failed attempt to login to GCL using notifications tickets
-
-
-
- 1002
- ^drupal
- mollom.getImageCaptcha
- Mollom outages
-
-
-
- 1002
- ^drupal
- All servers unavailable
- Mollom outages
-
-
-
- 1002
- ^drupal
- All servers unreachable or returning errors
- Mollom outages
-
-
-
- 1002
- ^drupal
- mollom.getServerList
- Mollom outages
-
-
-
- 1002
- ^drupal
- Oracle_Project_Failure_Cover
- Filename with the word failure
-
-
-
- 1003
- ^ovpn-openvpn
- PUSH_REPLY
- Large OpenVPN syslog message, pushing routes to the user
-
-
-
- 1003
- ^drupal
- gcl.prod.codeenigma.com:80/sugarcrm
- Large SugarCRM messsages
-
-
-
- 1003
- ^drupal
- www.gamblingcompliance.com/node
- Large Drupal watchdog messages
-
-
-
- 1003
- ^drupal
- www.gamblingcompliance.com/contact
- Large Drupal watchdog messages
-
-
-
- 1003
- ^drupal
- www.gamblingdata.com/contact
- Large Drupal watchdog messages
-
-
-
- 40101
- ^su
- root:nobody
- Crons from cron.daily
-
-
-
- 1003
- ^drupal
- www.gamblingcompliance.com/search/site
- Large Drupal watchdog messages
-
-
-
- 1003
- ^drupal
- Searched Site for
- Large Drupal watchdog messages
-
-
-
- 1002,1003
- ^drupal
- disallowed Unicode code
- Unicode errors due to sites that need updating so they work with current PHP versions
-
-
-
- 1002
- ^drupal|wcc
- Undefined property
- PHP warnings and errors
-
-
-
- 1002
- ^drupal|wcc
- Undefined variable
- PHP warnings and errors
-
-
-
- 1002,1003
- ^drupal|wcc
- Trying to get property of non-object
- PHP warnings and errors
-
-
-
- 1002
- ^drupal|wcc
- to be array,
- PHP warnings and errors
-
-
-
- 1002
- ^/USR/SBIN/CRON
- (CRON) error (grandchild #
- Failing crontabs
-
-
-
- 1002
- ^ovpn-openvpn
- Connection refused
- Disconnecting VPN clients
-
-
-
- 1002
- ^drupal
- Use of undefined constant
- PHP bugs in EC sites
-
-
-
- 1002,1003
- ^drupal|wcc
- Undefined index
- PHP bugs in sites
-
-
-
- 1002
- ^ovpn-openvpn
- TLS Error
- Disconnecting VPN clients
-
-
-
- 1002
- ^ovpn-openvpn
- tls-error
- Disconnecting VPN clients
-
-
-
- 1002
- ^ovpn-openvpn
- Bad LZO decompression header
- Disconnecting VPN clients
-
-
-
- 1003
- ^drupal
- Retrieved new CAPTCHA
- Verbose Mollom logging
-
-
-
- 1003
- ^drupal
- Incorrect CAPTCHA
- Verbose Mollom logging
-
-
-
- 1003
- rest.mollom.com
- Mollom messages are often too verbose and trip OSSEC on 1003
-
-
-
- 1002
- Finished processing scheduled jobs
- Job Scheduler in Drupal uses the word 'failed' even when 100% success. Ignore
-
-
-
- 1002
- Preventing ms_DRBD_NFS from re-starting on
- monitors can't run resources
-
-
-
- 1002
- ^nslcd
- request denied by validnames option
- Jenkins Duplicity jobs trigger nslcd verbose message
-
-
-
- 1002
- ^php
- No buffer to delete in /usr/share/php/pearcmd.php on line 19
- Ignore buggy pearcmd.php on PHP 5.4
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- failed with code
- Buggy feed app
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- Apache Solr
- Solr comm fail
-
-
-
- 1003
- airmic-app2.codeenigma.net
- ^drupal
- IDS Detector Details
- airmic civicrm
-
-
-
- 1003
- airmic-app2.codeenigma.net
- ^drupal
- apachesolr_search
- airmic solr
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- oauth_consumer_key
- airmic mollom
-
-
-
- 1002
- ^nagios3
- SOLR Cores
- Ignore automatic SOLR alerts on midnight
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- The page you requested is currently unavailable
- civicrm
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- Terrorism
- civicrm
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- DB Error: already exists
- civicrm
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- Could not find valid value for id
- civicrm
-
-
-
- 1003
- airmic-app2.codeenigma.net
- ^drupal
- backTrace
- civicrm
-
-
-
- 1003
- airmic-app2.codeenigma.net
- ^drupal
- civicrm
- Airmic CiviCRM
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- We can't load the requested web page
- Airmic CiviCRM
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- You do not have permission to access this page
- Airmic CiviCRM
-
-
-
- 1003
- airmic-app2.codeenigma.net
- ^drupal
- has answered your question
- Airmic CiviCRM
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- ERROR_CONTACT
- Airmic CiviCRM
-
-
-
- 1002
- ^nslcd
- Can't contact LDAP server
- Occasional connection closures on LDAP lookups from remote locations
-
-
-
- 1002
- ^rngd
- FIPS 140-2 failures
- rngd-tools
-
-
-
- 1002,1003
- ^drupal|wcc
- Invalid argument supplied for foreach
- Bug in site
-
-
-
- 1002
- wt-stage2.codeenigma.net
- ^drupal
- SearchApiSolrConnection
- Badly configured Solr
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- Solr
- Badly configured Solr
-
-
-
- 1002
- ^drupal
- seems to be broken
- Bad feeds
-
-
-
- 1003
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- ^drupal
- swf.swf
- Bad URL
-
-
-
- 1002
- wt-app3.codeenigma.com|wt-app4.codeenigma.net
- ^drupal
- SearchApiSolrConnection
- Bad Solr config
-
-
-
- DatabaseConnection->escapeLike
- SQL attempt in form
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- failed with code 410
- Bad twitter feed
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- foreach
- Bad code
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- ^drupal
- aspxerrorpath
- Bad URL
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- stat failed
- Missing files
-
-
-
- 1002
- redactive-dev2.codeenigma.net
- ^drupal
- SearchApiException while optimizing Solr server
- Missing solr
-
-
-
- 1002
- ^drupal
- seems to be broken
- Bad feeds
-
-
-
- 1002
- ^drupal
- Bad RequestApache
- Bad solr
-
-
-
- 1002,1003
- terror|error.asp
- The word terror is not considered a hacking attack
-
-
-
- 1002
- bad|attack
- These words are harmless
-
-
-
- 1002
- ^systemd
- Failed to read PID from file
- Harmless bug
-
-
-
- 1002
- swift-app1.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app6.codeenigma.net
- Compilation failed
- Harmless bug
-
-
-
- 1002
- monitor3.codeenigma.net|monitor2.codeenigma.com
- ^nagios3
- SERVICE
- Noisy Nagios will alert us itself if there is a real problem
-
-
-
- 1002
- ^kernel
- floppy: error -5 while reading block 0
- Noise
-
-
-
- 1002
- ^systemd
- Failed to reset devices.list on /system.slice
- Noise
-
-
-
- 1002
- ^drupal
- check the manual that corresponds to your MySQL server version for the right syntax to use near
- Buggy code
-
-
-
- 1002
- ^drupal|cricknet
- Connection refused in SearchApiSolrConnection
- Ignore harmless solr error
-
-
-
- 1002
- monitor3.codeenigma.net
- ^ntop
- rrd_update
- Ignore nTop messages
-
-
-
- 1002
- Illegal string offset
- Noisy PHP bug
-
-
-
- 1002,1003
- wt-stage2.codeenigma.net
- ^drupal
- 401 Unauthorized
- Noisy stage sites
-
-
-
- 1002
- monitor3.codeenigma.net
- ^ovpn-openvpn
- AUTH_FAILED|TLS Auth Error|PLUGIN_AUTH_USER_PASS_VERIFY failed|SSL3_GET_CLIENT_CERTIFICATE
- Failed attempt to login to OpenVPN
-
-
-
- 1002
- ^drupal
- Error sending e-mail
- failed email send
-
-
-
- 1002
- jenkins2.codeenigma.net
- ^openvpn
- fail
- Ignore failing VPN
-
-
-
- 1002
- monitor3.codeenigma.net
- ^ovpn-openvpn
- bad packet ID
- Flaky OpenVPN clients
-
-
-
- 1002
- ^drupal
- The file upload failed
- Buggy client code or some other app issue
-
-
-
- 1003
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- mapping-ISOLatin1Accent.txt
- Solr noise
-
-
-
- 1002
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- Internal Server Error: Internal Server Error in apachesolr_cron
- Solr noise
-
-
-
- 1002
- Feed processing failed
- App noise
-
-
-
-
- 1002
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- The configuration file {/var/www/piwik/config/config.ini.php} has not been found or could not be read
- Piwik not installed
-
-
-
- 1002
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- An unexpected website was found in the request
- Piwik fail
-
-
-
- 1003
- ^drupal
- Reacting on event
- Large syslog messages on aps
-
-
-
- 1002
- nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net
- Connection refused
- Solr error
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net|wt-stage2.codeenigma.net
- ^drupal
- Invalid view mode
- Bad code
-
-
-
- 1002
- ^freshclam
- Can't find or parse configuration file /etc/clamav/clamd.conf
- Jessie upgrade
-
-
-
- 1003
- nycc-dev2.codeenigma.net|nycc-app3.codeenigma.net
- unknown field
- Noisy syslog message
-
-
-
- 1002
- nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net
- Name or service not known
- Noisy syslog message
-
-
-
- 1002
- nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net
- A fast 404 test
- Noisy syslog message
-
-
-
- 1002
- /usr/bin/filebeat
- SSL client failed to connect
- Ignore noisy disconnections
-
-
-
- 31421
- wt-stage2.codeenigma.net
- planer_three_region.inc
- Ignore noisy bug on WT stage
-
-
-
- 1002
- freshclam
- Can't download
- Ignore clamav outage
-
-
-
- 1002
- freshclam
- Connection refused
- Ignore clamav outage
-
-
-
- 1002
- drupal
- redactive-app3.codeenigma.net
- Undefined offset
- Ignore buggy code
-
-
-
- 1002
- monitor3.codeenigma.net|monitor2.codeenigma.com
- ^nagios3
- API returned error
- Buggy Pingdom or Statuscake
-
-
-
- 1002
- wt-stage2.codeenigma.net|wt-app3.codeenigma.net|wt-app4.codeenigma.net
- ^drupal
- Can't contact LDAP server
- Ignore LDAP alerts in Drupal
-
-
-
- 1002,1003
- Illegal offset type
- Buggy code
-
-
-
- 1003
- airmic-app2.codeenigma.net
- cron running apachesolr_nodeapi_mass_delete
- Harmless message
-
-
-
- 1002,1003
- Data too long for column
- Noisy MySQL exception
-
-
-
- 1002,1003
- wt-stage2.codeenigma.net
- swf.swf
- More awful coding by apparent professionals
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- TotalRequests Limit exceeded
- salesforce issue
-
-
-
- 3330
- ^postfix
- 451 Internal resource temporarily unavailable
- greylisting
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- is not of the type Positive
- civicrm issue
-
-
-
- 1002
- ^drupal
- bytes in _dmemcache_get_pieces()
- Bug in memcache module in distributed setups
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- failed to load destination URL
- ads issue
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- ^drupal
- error404
- false positive
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- chain
- false positive
-
-
-
- 1003
- ^drupal
- nycc-app3.codeenigma.net|nycc-dev2.codeenigma.net
- .asp
- Bot noise
-
-
-
- 1002
- ^varnishd
- VCL_MET_BACKEND_ERROR
- Normal Varnish reload
-
-
-
- 1002
- ^varnishd
- backend_error
- Normal Varnish reload
-
-
-
- 1002
- ^varnishd
- synth+error
- Normal Varnish reload
-
-
-
- 1002
- ^varnishd
- Return error code 405
- Normal Varnish reload
-
-
-
- 1002
- ^varnishd
- h1
- Normal Varnish reload
-
-
-
- 1002
- ^varnishd
- invisibly
- Normal Varnish reload
-
-
-
- 1002,1003
- ^drupal
- Missing bundle property on entity of type
- Buggy site
-
-
-
- drupal
- php module enabled
- PHP module has been enabled on this Drupal site
-
-
-
- 1002,1003
- ^drupal
- Data truncated for column
- Buggy site
-
-
-
- 1003
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- ^drupal
- EntityStructureWrapper
- Buggy site
-
-
-
- 1003
- swift-app1.codeenigma.net
- ^drupal
- doubleclick
- False positive
-
-
-
- 1002
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app6.codeenigma.net
- ^drupal
- from no-reply@stem.org.uk|Failed sending email
- Bad mail attempts
-
-
-
- 1002
- govwales-app3.codeenigma.net|govwales-app4.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- Request failed: Connection refused
- Bad solr
-
-
-
- 1002,1003
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- ^drupal
- field_organisation_target_id
- Buggy site
-
-
-
- 1003
- swift-app1.codeenigma.net
- ^drupal
- flashtalking
- Big referer
-
-
-
- 1002
- ^drupal|wcc
- as the parent data structure is not set
- Buggy site
-
-
-
- 1002
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- ^snmpd
- get_errorcounters
- SNMP message
-
-
-
- 1002,1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- Recieved
- Varnish noise
-
-
-
- 1002,1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- Authentication to server failed
- Varnish noise
-
-
-
- 1002,1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- Socket error
- Varnish noise
-
-
-
- 40111
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^varnishd
- CLI Authentication failure from telnet
- Varnish noise
-
-
-
- 1002,1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- Request failed
- Varnish noise
-
-
-
- 1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- CLI telnet
- Varnish noise
-
-
-
- 1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- Expiration was executed
- Varnish noise
-
-
-
- 1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- Rd ban req.http.host
- Varnish noise
-
-
-
- 1002
- ^drupal
- Unable to render media
- Buggy site
-
-
-
- 31412,31421,1002
- airmic-app2.codeenigma.net
- adserve.inc on line 274
- Buggy site
-
-
-
- 1003
- ^varnishd
- CLI telnet 127.0.0.1
- Varnish noise
-
-
-
- 1002
- redactive-app3.codeenigma.com
- ^drupal
- Unexpected error the MTL API
- 3rd party service down
-
-
-
- 1002
- puppet3.codeenigma.net
- failedbackupscheck
- Harmless script name
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- 500-unexpected-error-occured
- Noisy 404s
-
-
-
- 1002
- ^dockerd
- be forced
- Noisy docker cleanup
-
-
-
- 1002
- monitor3.codeenigma.net|monitor2.codeenigma.com
- ^nagios3
- A TLS packet with unexpected length was received
- Flaky network
-
-
-
- 1002
- monitor3.codeenigma.net|monitor2.codeenigma.com
- ^nagios3
- Empty reply from server
- Flaky network
-
-
-
- 1002
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- ^drupal
- failed to open file handle
- Buggy code
-
-
-
- 1003
- swift-app1.codeenigma.net
- ^drupal-exacom
- exa_rules
- Noisy code
-
-
-
- 1002,1003
- swift-app1.codeenigma.net
- ^drupal
- Attempting to re-run cron while it is already running
- cron collision
-
-
-
- 1002
- ^sshd
- no matching cipher found
- crawler
-
-
-
- 1002
- monitor3.codeenigma.net|monitor2.codeenigma.com
- ^nagios3
- Was both Username and API Key provided
- crawler
-
-
-
- 1002
- airmic-app2.codeenigma.net
- ^drupal
- PEAR_ErrorStack::singleton
- deprecated code
-
-
-
- 1002,1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ^drupal
- rbipdebug
- debug code
-
-
-
- 1002
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- __clone method called on non-object in
- buggy code
-
-
-
- 1002,1003
- wt-stage2.codeenigma.net
- ^drupal
- SearchApiException while
- buggy code
-
-
-
- 1002,1003
- airmic-app2.codeenigma.net
- ^simplesamlphp
- Use of undefined constant AIRMIC_SIMPLESAMLPHP_SAML20_IDP_REMOTE
- buggy code
-
-
-
- 1002,1003
- airmic-app2.codeenigma.net|hlt-app1.codeenigma.net|rcpch-dev2.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- ^simplesamlphp|SimpleSAMLphp
- Error|Headers|errors
- buggy code
-
-
-
- 1002
- The following module is missing from the file system
- Noisy code
-
-
-
- 1002,1003
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- ^drupal
- METADATANOTFOUND
- buggy code
-
-
-
- 1003
- no_email_alert
- Silence the 1003 alerts
-
-
-
- 1002
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- Broken pipe in _clamav_scan_via_daemon
- Not a security issue
-
-
-
- 1002
- ^drupal|wcc
- SMTP error: Could not authenticate
- Not a security issue
-
-
-
- 1002
- swift-app1.codeenigma.net
- ^drupal|wcc
- Lost connection to MySQL server during query
- MySQL crash or slow queries need optimising
-
-
-
- 1002
- wt-stage2.codeenigma.net
- ^drupal
- Revert
- False positive
-
-
-
- 31421
- ^php
- Call to undefined function apc_clear_cache
- False positive
-
-
-
- 1002
- Failed opening
- Buggy code
-
-
-
- 1002
- ^drupal
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- occurred when trying to fetch
- stage_file_proxy error
-
-
-
- 1002
- ^dnsmasq
- monitor3.codeenigma.net
- Operation not permitted
- caused by someone in the VPN
-
-
-
- 1002
- ^drupal
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- Error fetching data from
- 3rd party service
-
-
-
- 1002
- ^drupal
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- Unknown error
- Noise
-
-
-
- 1002
- airmic-app2.codeenigma.net
- link.vars.php
- Noise
-
-
-
- 1002
- ^drupal
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- Connection refused
- Noise
-
-
-
- 1002
- airmic-app2.codeenigma.net
- Duplicate entry
- Noise
-
-
-
- 1002
- ^drupal
- redactive-dev2.codeenigma.net
- Connection refused
- Noise
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- Do_not_worry_about_it
- Noise
-
-
-
- 1002
- ^rrdcached
- monitor3.codeenigma.net
- found extra data on update argument
- Bug in rrdcached
-
-
-
- 1002
- ^rrdcached
- monitor3.codeenigma.net
- failed with status
- Bug in rrdcached
-
-
-
- 1002
- nycc-app3.codeenigma.net
- libssh2.so
- php bug
-
-
-
- 1002
- ^drupal
- myscience-dev3.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net
- API call to
- Ignore Stem API errors
-
-
-
- 1002
- ^drupal
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net
- User account creation error
- Ignore Stem API errors
-
-
-
- 1002
- ^drupal
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net
- Wrong return data for
- Ignore Stem API errors
-
-
-
- 1002,1003
- ^drupal
- myscience-dev3.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net
- Base table or view not found
- Ignore Stem errors
-
-
-
- 1002,1003
- ^drupal
- myscience-dev3.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app6.codeenigma.net
- Error creating/updating Achiever contact
- Ignore Stem errors
-
-
-
- 1002
- hlt-app1.codeenigma.net
- Validation with key
- Ignore SimpleSAML errors
-
-
-
- 1002
- airmic-app2.codeenigma.net
- Cannot redeclare class
- PHP site bug
-
-
-
- 1002
- redactive-app3.codeenigma.net
- Error opening socket
- false positives
-
-
-
- 1002
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- Login denied from
- noisy alert
-
-
-
- drupal
- Potentially unsafe keys
- Potentially unsafe keys found in request parameters
-
-
-
- 1002
- AcquiaSearchService
- Noisy solr bug
-
-
-
- 1002
- govwales-ldn-dev2.codeenigma.net
- doc.rtl
- Noisy site bug
-
-
-
- 1002
- ^drupal
- Unknown error
- Drupal noise
-
-
-
- 1002
- ^CRON
- Cron error
- Epiqo cronjob noise
-
-
-
- 1002
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net|govwales-ldn-app6.codeenigma.net
- The resource owner or authorization server denied the request
- Noisy
-
-
-
- 1002
- SimpleSAML_Error|NOSTATE|UNHANDLEDEXCEPTION
- Noise
-
-
-
- 1002
- ^drupal
- HTTPRedirect
- Noise
-
-
-
- 1002,1003
- Headers already sent
- buggy code
-
-
-
- 1002
- access-denied|ShowErrors|failedattempt|User_error|AH00036|AH02032|display_errors|valid-user|RequireAny|FailedURI|user_refused|i2cerrors|aspxerrorpath|No such file or directory|trial-and-error|AH01991|AH00687|Failure.ppt|advagg|fatal-fire|failure.jpg|on_error|judging-our-errors|20fail|locationError|permissiondenied|AH01996|SSL23_GET_CLIENT_HELLO|supermarket-refused|moodle_exception|ERROR_CONTACT_SUPPRESSED|failed=1|_refused|errors-|error-404|error_|-error|98failure|error.png|fatale|_error
- normal 403s
-
-
-
- 1002,1003
- fci-dev2.codeenigma.net
- ^cricknet
- Unable to get a data value
- buggy code
-
-
-
- 1002
- ^ovpn
- TLS key negotiation failed|TLS handshake failed
- port-scanning VPN servers is noisy
-
-
-
- 1002
- ^drupal
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- Failed to push json to s3
- Site bug
-
-
-
- 1002
- ^drupal
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app4.codeenigma.net
- Call to a member function getCompanyNo
- Noisy site bug
-
-
-
- 1002
- ^cron-nsfailover
- Operation not permitted
- Noisy stretch alert
-
-
-
- 1002
- ^agent
- jmxfetch
- Noisy alert
-
-
-
- 1002
- ^drupal
- Queue size
- Noisy Drupal alert
-
-
-
- 1002
- ^puppet-agent
- Composer
- Noisy Puppet alert
-
-
-
- 1002
- ^dockerd
- cgroup path for memory not found
- Noisy Docker alert
-
-
-
- 1002
- ^puppet-agent
- ffaker
- Noisy alert
-
-
-
- 1002
- myscience-dev3.codeenigma.net|myscience-dev4.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app5.codeenigma.net|myscience-app6.codeenigma.net
- Argument 1 passed to
- Noisy alert
-
-
-
- 1002
- ^drupal
- Could not connect to Mailchimp
- Noisy alert
-
-
-
- 5501,5502
- git2.codeenigma.net|jenkins2.codeenigma.net|iaea-utilities2.codeenigma.net|govwales-utility2.codeenigma.net|nycc-utility2.codeenigma.net|myscience-utility1.codeenigma.net|airmic-utility2.codeenigma.net
- ^sshd
- for user git
- Noisy alert
-
-
-
- 5715
- git2.codeenigma.net|jenkins2.codeenigma.net|iaea-utilities2.codeenigma.net|govwales-utility2.codeenigma.net|nycc-utility2.codeenigma.net|myscience-utility1.codeenigma.net|airmic-utility2.codeenigma.net
- ^sshd
- Accepted publickey for git
- Noisy alert
-
-
-
- 1002,1003
- govwales-ldn-dev2.codeenigma.net|govwales-ldn-app3.codeenigma.net|govwales-ldn-app4.codeenigma.net
- ShieldMiddleware
- Noisy alert
-
-
-
- 1002
- myscience-dev3.codeenigma.net|myscience-dev4.codeenigma.net|myscience-dev5.codeenigma.net|myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-app5.codeenigma.net|myscience-app6.codeenigma.net
- Problem processing JSON
- Noisy alert
-
-
-
- 1002
- ^awslogs
- is not running
- Noisy alert
-
-
-
- 1002
- ^amazon-ssm-agent
- AccessDeniedException|Failed|error
- Noisy alert
-
-
-
-
-
-
-
-
-
- drupal
- Drupal
- Drupal syslog message
-
-
-
- 104110,1002
- Login attempt failed
- Drupal failed login!
-
-
-
- 104120
-
- Login attempt failed for admin.
- Drupal failed attempt to log in as admin!
-
-
-
- 104120
- Possible Drupal brute force attack
- (high number of logins).
-
-
-
-
- 104110
- Illegal choice
- Drupal possible input injection (XSS/XSRF) attack!
-
-
-
- 104110,1002
- Access denied
- Drupal access denied error (permissions rejected).
-
-
-
- 104150
- admin/
- Drupal access denied to admin screen.
-
-
-
-
-
-
-
-
-
- 31122
- GET /sites/default/files/styles
- Unable to generate derived image in Drupal - ignored
-
-
-
- 1002
- markets-and-market-failure
- False positive due to name of URL
-
-
-
- 31151
- iepngfix.htc
- Missing image on thorogood site
-
-
-
- 31151,31115
- flashtalking/ftlocal.html
- Broken ads on revisionworld.co.uk
-
-
-
- 31122
- POST /node/add/study_calendar
- Broken app on revisionworld.co.uk
-
-
-
- 31151
- Preloader10.swf
- Broken app on revisionworld.co.uk
-
-
-
- 31151,31115
- DARTIframe
- Broken app on revisionworld.co.uk
-
-
-
- 31151
- wmode=transparent
- Broken app on revisionworld.co.uk
-
-
-
- 1003
- GET /production/catalog
- Puppet check-ins create a large syslog message, ignore it
-
-
-
- 1003
- GET /stage/catalog
- Puppet check-ins create a large syslog message, ignore it
-
-
-
- 1003
- GET /dev/catalog
- Puppet check-ins create a large syslog message, ignore it
-
-
-
- 31122
- 500 5 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
- Googlebot 500 errors (on GCL site)
-
-
-
- 1002
- LookupIdVisitor
- EC Asia errors seen in nginx log
-
-
-
- 1003
- GET /issues/context_menu
- Large redmine apache access logs
-
-
-
- 1003
- GET /projects/gcl
- Large redmine apache access logs
-
-
-
- 31151
- FlipboardProxy
- FlipboardProxy logs 499 error code particularly on GCL
-
-
-
- 31153
- trusted-sources
- googlebot going bananas on paginated parts of the variantperception site
-
-
-
- 31151
- atlas_js_shared.js
- Missing javascript file triggering 404 active response
-
-
-
- 31122
- GET /en/sites/default/files/styles
- imagecache from bots on codeenigma site
-
-
-
- 31122
- GET /fr/sites/default/files/styles
- imagecache from bots on codeenigma site
-
-
-
- 31122
- "POST /user/register HTTP/1.1" 500 5 "http://www.gambling
- bots on GCL site
-
-
-
- 31152
- enigma3.codeenigma.net
- web-accesslog
- photos-for-sale
- Strange Thorogood URLs interpreted as SQL injection attacks
-
-
-
- 31123
- /var/log/nginx/access-support.prod.log
- web-accesslog
- "GET / HTTP/1.1" 503
- Googlebot hitting a site that is offline
-
-
-
- 31123
- /var/log/nginx/access-the-planner.prod.log
- web-accesslog
- HTTP/1.1" 503
- Site is in maintenance mode
-
-
-
- 31122
- /var/log/nginx/access-spring.log
- web-accesslog
- 500
- Internal server error on this site
-
-
-
- 31151
- web-accesslog
- GET /sites/default/files/styles
- Common location for 403 or 401 codes on Drupal imagecache
-
-
-
- 31122
- web-accesslog
- ++++++++++++++++++++++++++++Result
- Spambots
-
-
-
- 31151
- web-accesslog
- /var/log/nginx/access-sm.prod.log
- feed
- RSS crawling bot
- no_email_alert
-
-
-
-
-
- 31151
- web-accesslog
- /var/log/nginx/access-sm.prod.log
- getresource.axd
- Broken ad 404ing probably trips OSSEC and user access
-
-
-
- 31151
- web-accesslog
- /var/log/nginx/access-airmic.prod.log
- CRM_Contact_Page
- Client doing something with ajax in civicrm that throws spurious 499 codes
-
-
-
- 31151
- web-accesslog
- /var/log/nginx/access-airmic.prod.log
- boost-gzip-cookie-test.html
- Client doing something with ajax in civicrm that throws spurious 499 codes
-
-
-
- 31151
- /var/log/apache2/access-tcs-intranet.log
- itok
- Requesting various assets seems to result in a 403 at least temporarily, trips OSSEC and likely blocks users
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- admanmedia
- Residual 404s on WT due to re-used IP on loadbalancer from a previous customer
-
-
-
- 31151
- /var/log/nginx/access-bigpicture.prod.log
- eot
- 404s on Big Picture site
-
-
-
- 31151
- /var/log/nginx/access-bigpicture.prod.log
- fast_facts/json/all
- 403s on Big Picture site
-
-
-
- 31101
- Microsoft Office Protocol Discovery
- Probably an OPTIONS request from Microsoft Office Protocol Discovery user-agent
-
-
-
- 31151
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- admanmedia
- Residual 404s on WT due to re-used IP on loadbalancer from a previous customer
-
-
-
- 31153
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- admanmedia
- Residual 404s on WT due to re-used IP on loadbalancer from a previous customer
-
-
-
- 31122
- /var/log/nginx/access-sm.prod.log
- HTTP/1.1" 500
- 500s on Supply Management site
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- message-24-error.png
- harmless jpeg
-
-
-
- 31151
- /var/log/nginx/access.org.log|/var/log/nginx/access-actionaid.org.log
- aaidonazione/confirmDonation.do?codeTransaction
- 404s every 30 min or so on ActionAid from Italy to some donation page
-
-
-
- 31151
- OPTIONS /system
- Microsoft silliness
-
-
-
- 31151,31122
- PROPFIND /system
- Microsoft silliness
-
-
-
- 31151
- chsoc-app2.codeenigma.net
- /user/login/sso
- SSO component on CHSOC sites
-
-
-
- 31151
- chsoc-app2.codeenigma.net
- OPTIONS
- Misbehaving browsers on chsoc
-
-
-
- 1002
- Method has been changed to GET
- Ignore broken links in linkchecker module reporting to watchdog
-
-
-
- 31101
- web-accesslog
- /bin/bash
- Shellshock attempt
-
-
-
- 31101
- redactive-app3.codeenigma.net
- web-accesslog
- bkg-header.png
- 404s
-
-
-
- 31101
- /var/log/nginx/access-ecg.log
- web-accesslog
- medmastery.com
- 403s
-
-
-
- 31101
- /var/log/nginx/access-ecg.log
- web-accesslog
- course
- 403s
-
-
-
- 1003
- gclid
- Ignore large weblog with big Referer (google ad?)
-
-
-
- 31101
- redactive-app3.codeenigma.net
- web-accesslog
- GET /news-feed.rss
- ignore 404
-
-
-
- 31101
- redactive-app3.codeenigma.net
- web-accesslog
- GET /newsrss.rss
- ignore 404
-
-
-
- 31530,31108
- ] "POST \S+.php\.+HTTP/1.\." 200
- POST request to a file ending in .php extension
-
-
-
- 31530,31108
- ] "POST \S+.html
- POST request to a file ending in .html extension
- no_email_alert
-
-
-
- 31122
- redactive-app3.codeenigma.net
- \\x
- 500 errors with strange characters in the URLs, seems to recur on occasion
-
-
-
- 101100,1002
- jstats|kibana|geocoding
- Stats
-
-
-
- 101100
- statistics.php
- Stats
-
-
-
- 101100
- wp-admin
- Normal Wordpress activity
-
-
-
- 31101
- redactive-app3.codeenigma.net
- web-accesslog
- 85.232.51.149
- GET /opinion/header
- 404s
-
-
-
- 31122,1002
- /var/log/nginx/access-mapmeo.log|/var/log/nginx/access-www.meinestelle.de.log|/var/log/nginx/access-empla.log|/var/log/nginx/access-unicum.log
- hybridauth
- Broken Epiqo app
-
-
-
- 1002,1003,31123
- terror|bad|attack|error.asp|errordetail1|Error.aspx|error.svg|planning-error|failures|error500|failed_uli|channelling-failure|Error%20|-failure|-failed|-illegal|search-error|failure-
- The word terror is not considered a hacking attack
-
-
-
- 101100
- redactive-app3.codeenigma.net|redactive-dev2.codeenigma.net
- emit.php
- Stats
-
-
-
- 31101
- redactive-dev2.codeenigma.net|redactive-app3.codeenigma.net
- web-accesslog
- feed
- ignore 404
-
-
-
- 30101
- /var/log/apache2/error.log
- server reached MaxClients setting, consider raising the MaxClients setting
- MaxClients threshold reached
-
-
-
- 31122
- /var/log/nginx/access-revisionworld.log
- Buggy revisionworld
-
-
-
- /var/log/nginx/access-scambs-drupal.prod.log
- POST /user
- no_email_alert
- Ignore user post
-
-
-
- 101131
- Possible Drupal brute force attack
- (high number of requests to /user).
- no_email_alert
-
-
-
- 1002
- /var/log/nginx/access-actionaid.org.log
- abad|ebad
- Ignore URL
-
-
-
- 101100
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- machform
- Machform is OK to POST to
-
-
-
- 31122
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- piwik.php
- Piwik broken or not installed
-
-
-
- 1003
- search.yahoo.com
- Big referer
-
-
-
- 101055
- OPTIONS
- OPTIONS request from Microsoft Office Protocol Discovery user-agent
-
-
-
- 101100
- airmic-app2.codeenigma.net|enigma3.codeenigma.net
- xmlrpc
- POST to apparently OK script
-
-
-
- 1003
- jsredir
- Noisy Yandex
-
-
-
- 1002
- /misc/message-24-error.png
- false positive word
-
-
-
- 31533
- POST /batch?
- Normal to see high rate of POSTs to batch pages in Drupal
-
-
-
- 31122
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- mwt_republish/nojs
- Buggy code
-
-
-
- 31151
- /var/log/nginx/access-corporate.prod.log
- Ignore 404s on newly launched site for now
-
-
-
- 101100
- jdi-dev1.codeenigma.net|jdi-app2.codeenigma.net|jdi-app3.codeenigma.net|jdi-app4.codeenigma.net
- limesurvey
- Normal POST request
-
-
-
- 1002
- /var/log/apache2/error-iaea.master.log
- from remote server
- Bugs with IAEA remote legacy app
-
-
-
- 1003
- /var/log/nginx/access-unitedway.log
- job_geo_location
- Large nginx log messages
-
-
-
- 31161
- swift-app1.codeenigma.net
- sites/revisionworld.com/files
- Deliberate 501 code on revisionworld.com
-
-
-
- 1002
- wt-app3.codeenigma.net|wt-app4.codeenigma.net
- mwt-republish-img
- Noisy referer
-
-
-
- 31533
- /var/log/nginx/access-stem.prod.log
- js/shs/json
- Normal high rate of POSTs to Stem site
-
-
-
- 31122
- /var/log/nginx/access-stem.prod.log
- system/ajax
- Buggy site
-
-
-
- 101100
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- ^drupal
- idp
- Big IDP request
-
-
-
- 1002,1003
- redactive-dev2.codeenigma.net
- ^drupal
- 401 Unauthorized
- Noisy stage sites
-
-
-
- 31151,31101
- /var/log/nginx/access-smartsolutions.prod.log
- Ignore 40X in logs on nycc-app1 smartsolution site, there are too many 401s/404s due to site rebuild
-
-
-
- 101100
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- drupalauth
- SAML auth
-
-
-
- 31151,31152,31153,31154
- OpenVAS
- 127.0.0.1
- no_email_alert
- Too noisy
-
-
-
- 1003
- myscience-app3.codeenigma.net|myscience-app4.codeenigma.net|myscience-dev3.codeenigma.net|myscience-app6.codeenigma.net
- SSOService.php
- SAML auth
-
-
-
- 1002
- /var/log/nginx/access-govwalesd7.master.log
- care-and-support-business-failure-wales-regulations-2015-and-care-and-support
- False positive
-
-
-
- 1002
- /var/log/nginx/access-sono.log
- abdominal
- False positive
-
-
-
- 31533
- /var/log/nginx/access-bookworks.log
- publishing
- Frequent high rate of POSTs
-
-
-
- 31122
- /var/log/nginx/access-hosting-dashboard.prod.log
- StatusCake
- bad deploy
-
-
-
- 31123
- /var/log/nginx/access-ai.prod.log|/var/log/apache2/access-cwh.prod.log
- web-accesslog
- maint mode
-
-
-
- 31123
- /var/log/nginx/access-stem.amb_dev.log
- web-accesslog
- maint mode
-
-
-
- 31101,31151
- web-accesslog
- /var/log/nginx/access-recruiter.prod.log
- rss
- RSS crawling bot
- no_email_alert
-
-
-
- 31101,31151
- web-accesslog
- /var/log/nginx/access-recruiter.prod.log
- national-news.xml
- RSS crawling bot
- no_email_alert
-
-
-
- 31101,31151
- web-accesslog
- /var/log/nginx/access-thorogood.prod.log
- leaflet
- Buggy
-
-
-
- 31122
- web-accesslog
- /var/log/apache2/access-festival_micro.prod.log
- Buggy
-
-
-
- 31101,31151
- web-accesslog
- /var/log/nginx/access-wcc.ce-prod.log
- panels|planning|guide
- Buggy
-
-
-
- 31122
- web-accesslog
- /var/log/nginx/access-bookworks.log
- imagecache
- Meh
-
-
-
- 31533
- /var/log/nginx/access-rcm.prod.log
- POST /cas/login
- Normal to see high rate of POSTs to /cas/login pages
-
-
-
- 31122
- /var/log/nginx/access-hosting-dashboard.prod.log
- favicon.png
- Buggy code
-
-
-
- 31533
- /var/log/nginx/access-stem.prod.log
- POST /plupload-handle-uploads
- Normal to see high rate of POSTs to /plupload-handle-uploads pages
-
-
-
- 31123
- /var/log/nginx/access-hav-j150709.prod.log|/var/log/nginx/access-pri-j150281.prod.log
- web-accesslog
- site offline
-
-
-
- 1002
- /var/log/nginx/access-the-planner.prod.log
- failure|error|refused|denied|illegal
- false positive
-
-
-
- 1002
- message-16-error.png
- false positive in omega theme
-
-
-
- 1002,31122
- /var/log/nginx/access-mapmeo.log
- jserror
- false positive
-
-
-
- 31122
- /var/log/apache2/access-cwh.prod.log
- major-works
- site bug
-
-
-
- 101100
- enigma3.codeenigma.net
- wp-cron.php
- Wordpress
-
-
-
- 31151
- Jorgee
- no_email_alert
- Noisy scanner
-
-
-
- 31122,1002
- /var/log/nginx/access-unicum.log
- inhalt
- False positive
-
-
-
- 31122,1002
- /var/log/nginx/access-platform-prod.log
- api
- Noise I cannot do anything about
-
-
-
- 31122,1002
- /var/log/nginx/access-rcm.prod.log
- print|news-views-and-analysis|rss
- Noise I cannot do anything about
-
-
-
- 31122,1002
- /var/log/nginx/access-platform-prod.log
- platform
- Noise I cannot do anything about
-
-
-
- 31151,31101
- /var/log/nginx/access-platform-prod.log
- Ignore 40X on STEM platform
-
-
-
- 31123
- /var/log/nginx/access-actionaid.org.log|/var/log/nginx/access.org.log
- Ignore 503s on AAI (bots being rate-limited)
-
-
-
- 31122,1002
- /var/log/nginx/access-ecgstage.log
- chargebee
- bug on ECG stage site
-
-
-
- 1002
- /var/log/nginx/access-govwalesd8.master.log
- common-errors
- false positive
-
-
-
- 1002
- /var/log/nginx/access-cambridge.gov.uk.prod.log
- BuildFailureDetector
- False positive
-
-
-
- 31108,31101
- 23value|23default_value|23markup|element_parents=%23
- web-accesslog
- RCE attempt maybe
- no_email_alert
-
-
-
- 31122
- /var/log/apache2/access-rcm.prod.log
- rss.xml
- Site bug
-
-
-
- 31122
- myscience-dev4.codeenigma.net
- Site bug
-
-
-
- 31122
- /var/log/nginx/access-jpoesen.com.log
- web-accesslog
- comment/reply
- Internal server error on this site
-
-
-
- 31122
- /var/log/apache2/access-iaea.master.log|/var/log/apache2/access-iaea.drupal-direct.log
- Buggy site
-
-
-
- 1002
- client denied by server configuration
- 403d response
- no_email_alert
-
-
-
- 1002
- 2fa.codeenigma.net
- wsgi:error
- Bugs in LinOTP
-
-
-
- 31530
- /var/log/nginx/access-corporate.prod.log
- general-enquiry
- Possible spamming of WT corporate contact form
-
-
-
-
- 1002
- access-denied|ShowErrors|failedattempt|User_error|AH00036|AH02032|display_errors|valid-user|RequireAny|FailedURI|user_refused|i2cerrors|aspxerrorpath|No such file or directory|trial-and-error|AH01991|AH00687|AH01276|Failure.ppt|advagg|fatal-fire|failure.jpg|on_error|judging-our-errors|20fail|locationError|permissiondenied|AH01996|SSL23_GET_CLIENT_HELLO|supermarket-refused|moodle_exception|ERROR_CONTACT_SUPPRESSED|failed=1|_refused|errors-|error-404|error_|-error|98failure|error.png|fatale|_error
- normal 403s
-
-
-
- /var/log/apache2/access-cwh.prod.log
- Ignore 404s on cwh for now to avoid blocking users being proxied from HAproxy
-
-
-
- /var/log/apache2/access-wcc.ce-prod.log
- 31101,31151,1002
- fa-solid-900
- Ignore missing font files on new WCC site
-
-
-
- 101100
- /var/log/nginx/access-wcc.ce-prod.log|/var/log/nginx/access-johnthorogood.prod.log
- wp-login.php
- False positive
-
-
-
- 31101,31151,1002
- /var/log/nginx/access-tephinet.master.log|/var/log/nginx/access-tephinet.staging.log
- GET /sites/tephinet/files/styles
- Ignore missing style files on Mantaray Tephinet site
-
-
-
- 31151,31101
- wt-stage2.codeenigma.net
- Ignore 40X in logs on wt-stage2, there are too many 401s/404s due to misbehaving apps
-
-
-
-
-
-
-
-
- 31120
- ^502
- Web server 502 error code (Bad gateway).
-
-
-
- 31124
- /var/log/nginx/access-actelion.log
- web-accesslog
- Ignore 502s that we can't be responsible for (legacy sites)
-
-
-
- 31123
- /var/log/nginx/access-nycc.prod.log
- Strange 503s
-
-
-
-
-
-
- 521
- scantem
- Whitelist alerts containing 'scantem' in the title.
- no_full_log
-
-
-
+
+
+
+
+
+
+ 5716
+ 1.1.1.1
+ sshd: authentication failed from IP 1.1.1.1.
+ authentication_failed,pci_dss_10.2.4,pci_dss_10.2.5,
+
+
+
+
+
+ 521
+ scantem
+ Whitelist alerts containing 'scantem' in the title.
+ no_full_log
+
+
+
+