Wazuh解码器无法提取数据,请求协助配置三类事件解析规则
Wazuh解码器配置修复方案
问题背景
需要为某应用配置Wazuh解码器,提取连接登录、命令执行、断开连接三类事件的字段(用户名、IP、端口、命令、用户ID等),但现有解码器无法匹配日志。
日志样本
[Sat 19:24:16 INFO Event/User] usernameishere[/123.456.789:5432] logged in with user id 1046770 at ([h18n5]randomstringhere) [Sat 19:24:33 INFO Event/User] usernameishere ran command: /command is here with spaces [Sat 19:24:43 INFO Event/User] usernameishere lost connection: reasonhere
原解码器问题
原解码器存在两个核心问题:
- 错误指定
<parent>json</parent>:日志是纯文本格式,并非JSON,父解码器配置完全不符。 - 正则匹配逻辑错误:比如登录日志中,
\S+会把usernameishere[/123.456.789:5432]整个当成用户名,无法正确拆分出IP和端口。
修正后的解码器配置
1. 通用前缀解码器
先匹配所有日志的固定前缀,简化后续解码器的正则:
<decoder name="app_common"> <regex>^\[(?<timestamp>\w+\s+\d+:\d+:\d+)\s+(?<level>[A-Z]+)\s+Event/User\]\s+</regex> </decoder>
2. 登录事件解码器
正确提取用户名、IP、端口、用户ID:
<decoder name="app_login"> <parent>app_common</parent> <regex>(?<username>\w+)\[\/(?<ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}):(?<port>\d+)\] logged in with user id (?<user_id>\d+) at \(\[\S+\]\S+\)</regex> <order>username, ip, port, user_id</order> </decoder>
3. 命令执行事件解码器
完整提取带空格的命令内容:
<decoder name="app_command"> <parent>app_common</parent> <regex>(?<username>\w+) ran command: (?<command>.*)</regex> <order>username, command</order> </decoder>
4. 断开连接事件解码器
提取用户名和断开原因:
<decoder name="app_disconnect"> <parent>app_common</parent> <regex>(?<username>\w+) lost connection: (?<reason>.*)</regex> <order>username, reason</order> </decoder>
验证方法
用Wazuh自带的ossec-logtest工具测试:
/var/ossec/bin/ossec-logtest
输入日志样本后,就能看到字段是否被正确提取。
内容的提问来源于stack exchange,提问作者kloud.
相关产品推荐
相关产品推荐

