-
Notifications
You must be signed in to change notification settings - Fork 212
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add detection of ASA access list events #270
Conversation
c2f8358
to
9484686
Compare
Extend 0060-firewall_rules so that it recognises "Deny" and "denied" as well as "DROP" Note: this also changes recognition of "%SEC-6-IPACCESSLOGP ... denied" which is now recognised as a 'Firewall drop event', rather than just 'Firewall rules grouped' Fixes wazuh#269
9484686
to
a4afcd8
Compare
Rebased to current master |
Hello Team,
Regards, |
Is this still an issue? Checking current git head, the ruleset has:
Now,
So AFAICS this should be working now, except perhaps a match like |
Closing this, it is manage by "wazuh-ruleset: Cisco rules and decoders improvements" wazuh/wazuh#7278 |
Note: this also changes recognition of "%SEC-6-IPACCESSLOGP ... denied" which is now recognised as a 'Firewall drop event', rather than just 'Firewall rules grouped'
Fixes #269