Ticket #42533: decoder_local_mac.xml

File decoder_local_mac.xml, 5.8 KB (added by jul_bsd@…, 11 years ago)
Line 
1<!-- @(#) $Id: decoder.xml,v 1.166 2010/06/15 12:52:01 dcid Exp $
2  -  OSSEC log decoder.
3  -->
4       
5
6<!-- Macos log decoder
7  - extract usb devices use
8  - chrome log
9  -  Examples:
10  - kernel[0]: USBMSC Identifier (non-unique): 00001680D775EA97 0x781 0x5408 0x10, 2
11Feb 15 20:21:34 HOST kernel[0]: USBMSC Identifier (non-unique): 574343344530333937333935 0x1058 0x1230 0x1050, 2
12  - Google Chrome Helper[50583]: Process unable to create connection because the sandbox denied the right to lookup com.apple.coreservices.launchservicesd and so this process cannot talk to launchservicesd. : LSXPCClient.cp #426 ___ZN26LSClientToServerConnection21setupServerConnectionEiPK14__CFDictionary_block_invoke() q=com.apple.main-thread
13  - Google Chrome Helper[50583]: Process unable to create connection because the sandbox denied the right to lookup com.apple.coreservices.launchservicesd and so this process cannot talk to launchservicesd.
14  - Google Chrome Helper[50583]: CGSLookupServerRootPort: Failed to look up the port for "com.apple.windowserver.active"
15Feb 20 11:20:36 HOST Google Chrome Helper[59050]: Process unable to create connection because the sandbox denied the right to lookup com.apple.coreservices.launchservicesd and so this process cannot talk to launchservicesd.
16  - Preview
17Feb 20 10:51:20 HOST Preview[33917]: It does not make sense to draw an image when [NSGraphicsContext currentContext] is nil.  This is a programming error. Break on void _NSWarnForDrawingImageWithNoCurrentContext() to debug.  This will be logged only once.  This may break in the future.
18
19  -->
20
21<!-- 'iptables' parent just refer to prefix 'kernel' -->
22<decoder name="usb-insert">
23  <parent>iptables</parent>
24  <prematch>USBMSC Identifier</prematch>
25  <regex offset="after_prematch">: (\S+) (\S+) (\S+) (\S+), \d+$</regex>
26<!-- Note: not sure why, but get 'decode-xml: Wrong field ' devicerelease' in the order of decoder 'usb-insert''
27http://ossec-docs.readthedocs.org/en/latest/syntax/head_decoders.html#element-decoder.order
28
29  <order>extra_data, extra_data, extra_data, extra_data,</order> NOK logtest
30  <order>extra_data, extra_data, extra_data, extra_data</order> OK logtest/NOK match
31  <order>serialid, vendorid, productid, devicerelease,</order> NOK
32  <order>serialid, vendorid, productid, devicerelease</order> NOK
33  <order>serialid, vendorid, productid, extra_data</order> OK logtest/NOK match
34-->
35  <order>extra_data, extra_data, extra_data, extra_data</order>
36</decoder>
37
38<decoder name="code-signing">
39 <parent>iptables</parent>
40 <prematch>^CODE SIGNING: cs_invalid_page</prematch>
41 <regex offset="after_prematch">p=\d+[(\S+)] final status 0x0, allowing (remove VALID) page </regex>
42 <order>extra_data</order>
43</decoder>
44
45<decoder name="WindowServer">
46  <program_name>^WindowServer</program_name>
47</decoder>
48
49<decoder name="console">
50  <program_name>^Console</program_name>
51</decoder>
52
53<decoder name="xpcproxy">
54  <program_name>^xpcproxy</program_name>
55</decoder>
56
57<decoder name="com.apple.appkit.xpc.openAndSavePanelService">
58  <program_name>^com.apple.appkit.xpc.openAndSavePanelService</program_name>
59</decoder>
60
61<decoder name="launchd">
62  <program_name>^com.apple.launchd.peruser</program_name>
63</decoder>
64
65<decoder name="secd">
66  <program_name>^secd</program_name>
67</decoder>
68
69<decoder name="com.apple.authd">
70  <program_name>^com.apple.authd</program_name>
71</decoder>
72
73<!-- BUG: match
74Feb 26 20:24:56 HOST com.apple.authd[71]: Succeeded authorizing right 'com.apple.ServiceManagement.daemons.modify' by client '/usr/libexec/UserEventAgent' [11] for authorization created by '/usr/libexec/UserEventAgent' [11] (12,0)
75-->
76<decoder name="SecurityServer">
77  <program_name>^SecurityServer</program_name>
78</decoder>
79
80<decoder name="universalaccessd">
81  <program_name>^universalaccessd</program_name>
82</decoder>
83
84<decoder name="preview">
85  <program_name>^Preview</program_name>
86</decoder>
87
88<decoder name="itunes">
89  <program_name>iTunes</program_name>
90</decoder>
91
92<decoder name="iconservices">
93  <program_name>com.apple.IconServicesAgent</program_name>
94</decoder>
95
96<decoder name="speechrecognition">
97  <program_name>com.apple.SpeechRecognitionCore.speechrecognitiond</program_name>
98</decoder>
99
100<decoder name="loginwindow">
101  <program_name>loginwindow</program_name>
102</decoder>
103
104<decoder name="UserEventAgent">
105  <program_name>UserEventAgent</program_name>
106</decoder>
107
108<decoder name="SecurityAgent">
109  <program_name>SecurityAgent</program_name>
110</decoder>
111
112<decoder name="usernoted">
113  <program_name>usernoted</program_name>
114</decoder>
115
116<decoder name="usbmuxd">
117  <program_name>com.apple.usbmuxd</program_name>
118</decoder>
119
120<decoder name="storeagent">
121  <program_name>storeagent</program_name>
122</decoder>
123
124<decoder name="ManagedClient">
125  <program_name>ManagedClient</program_name>
126</decoder>
127
128<decoder name="mds">
129  <program_name>mds</program_name>
130</decoder>
131
132<decoder name="appleeventsd">
133  <program_name>appleeventsd</program_name>
134</decoder>
135
136<decoder name="fseventsd">
137  <program_name>fseventsd</program_name>
138</decoder>
139
140<decoder name="ReportCrash">
141  <program_name>ReportCrash</program_name>
142</decoder>
143
144<decoder name="com.apple.internetaccounts">
145  <program_name>com.apple.internetaccounts</program_name>
146</decoder>
147
148<decoder name="com.apple.imfoundation.IMRemoteURLConnectionAgent">
149  <program_name>com.apple.imfoundation.IMRemoteURLConnectionAgent</program_name>
150</decoder>
151
152<decoder name="chrome">
153<!-- Note: not supported (program_name w space): https://groups.google.com/forum/#!topic/ossec-dev/_yD5W-axGG0
154  <program_name>Google Chrome Helper</program_name>
155  <prematch>^Google Chrome Helper</prematch>
156-->
157  <prematch>^Google</prematch>
158</decoder>
159
160<decoder name="GoogleSoftwareUpdateDaemon">
161  <program_name>GoogleSoftwareUpdateDaemon</program_name>
162</decoder>
163
164<decoder name="Dropbox">
165  <program_name>Dropbox</program_name>
166</decoder>
167
168<decoder name="soffice">
169  <program_name>soffice</program_name>
170</decoder>
171
172<!-- EOF -->