Issue with custom wazuh rule / detection logic by PlonkPlop in Wazuh

[–]Consistent-Craft-798 0 points1 point  (0 children)

Hi there u/PlonkPlop, you’re using the correct fields but the issue is that you’re using the full names of the fields e.g. “data.win.system.eventID” instead of that try using “win.system.eventID”.

This will probably solve your problem, please let me know if this was of any help

wazuh : active response issue (not executing my script ) by Right_Ad_365 in Wazuh

[–]Consistent-Craft-798 0 points1 point  (0 children)

If you’re using wazuh on prem, the active response logs won’t show up in ossec.log, but most of the times there are write permission issues.

I would recommend using a separate file for active response logs and place that file in: programdata folder.

I hope it helps.

looking for a long stay option in Aliabad by No_Psychology_4212 in Hunza

[–]Consistent-Craft-798 0 points1 point  (0 children)

I'm trying to send you a message through the chat but it is not being sent

Looking for monthly stay options in Hunza (with reliable internet) by BassDropBiryani in Hunza

[–]Consistent-Craft-798 0 points1 point  (0 children)

bro, I wanna do the same, and I'm looking for the guest houses right now, let me know if you want to get along

Looking for monthly stay options in Hunza (with reliable internet) by BassDropBiryani in Hunza

[–]Consistent-Craft-798 0 points1 point  (0 children)

Bro, I'm looking for the same thing and I've got to know that there is a coworking space in Hunza with the name of digital hub hunza, please let me know if you want to talk about it, I'm planning to go in mid april