You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wazuh解码器无法提取数据,请求协助配置三类事件解析规则

Wazuh解码器配置修复方案

问题背景

需要为某应用配置Wazuh解码器,提取连接登录、命令执行、断开连接三类事件的字段(用户名、IP、端口、命令、用户ID等),但现有解码器无法匹配日志。

日志样本

[Sat 19:24:16 INFO  Event/User] usernameishere[/123.456.789:5432] logged in with user id 1046770 at ([h18n5]randomstringhere)
[Sat 19:24:33 INFO  Event/User] usernameishere ran command: /command is here with spaces
[Sat 19:24:43 INFO  Event/User] usernameishere lost connection: reasonhere

原解码器问题

原解码器存在两个核心问题:

  1. 错误指定<parent>json</parent>:日志是纯文本格式,并非JSON,父解码器配置完全不符。
  2. 正则匹配逻辑错误:比如登录日志中,\S+会把usernameishere[/123.456.789:5432]整个当成用户名,无法正确拆分出IP和端口。

修正后的解码器配置

1. 通用前缀解码器

先匹配所有日志的固定前缀,简化后续解码器的正则:

<decoder name="app_common">
  <regex>^\[(?<timestamp>\w+\s+\d+:\d+:\d+)\s+(?<level>[A-Z]+)\s+Event/User\]\s+</regex>
</decoder>

2. 登录事件解码器

正确提取用户名、IP、端口、用户ID:

<decoder name="app_login">
  <parent>app_common</parent>
  <regex>(?<username>\w+)\[\/(?<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}):(?<port>\d+)\] logged in with user id (?<user_id>\d+) at \(\[\S+\]\S+\)</regex>
  <order>username, ip, port, user_id</order>
</decoder>

3. 命令执行事件解码器

完整提取带空格的命令内容:

<decoder name="app_command">
  <parent>app_common</parent>
  <regex>(?<username>\w+) ran command: (?<command>.*)</regex>
  <order>username, command</order>
</decoder>

4. 断开连接事件解码器

提取用户名和断开原因:

<decoder name="app_disconnect">
  <parent>app_common</parent>
  <regex>(?<username>\w+) lost connection: (?<reason>.*)</regex>
  <order>username, reason</order>
</decoder>

验证方法

用Wazuh自带的ossec-logtest工具测试:

/var/ossec/bin/ossec-logtest

输入日志样本后,就能看到字段是否被正确提取。

内容的提问来源于stack exchange,提问作者kloud.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 02:00:31