Ejemplo cutre de decoder/rules para que OSSEC entienda el vpxd.log de VMWare Virtual Center (Probado en vCenter 4).
Decoder
<!-- VMWare Virtual Center vpxd logs.
- [2010-04-29 13:42:52.048 03572 warning 'Libs'] SSLVerifyCertAgainstSystemStore: The remote host certificate has these problems:
- [2010-04-29 11:46:47.101 02144 info 'App'] [Auth]: User DOMAIN\luser
- [2010-04-29 13:54:54.406 02656 info 'App'] Unable to log on locally as DOMAIN\Administrator, so switched to NETWORK-style logon
-->
<decoder name="vpxd">
<prematch>^[\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d.\d\d\d \d+ </prematch>
</decoder>
<decoder name="vpxd-extra">
<parent>vpxd</parent>
<regex offset="after_parent">^(\w+) '\w+'] (\.+)</regex>
<order>status, extra_data</order>
</decoder>
Rules
<!-- VMWare Virtual Center vpxd -->
<group name="vpxd,">
<rule id="19200" level="0">
<decoded_as>vpxd</decoded_as>
<description>VMWare Virtual Center vpxd messages grouped.</description>
</rule>
<rule id="19201" level="4">
<if_sid>19200</if_sid>
<status>^warning</status>
<description>VMWare Virtual Center vpxd warning message.</description>
</rule>
<rule id="19202" level="8">
<if_sid>19200</if_sid>
<status>^error</status>
<description>VMWare Virtual Center vpxd error message.</description>
</rule>
<rule id="19203" level="0">
<if_sid>19200</if_sid>
<status>^info</status>
<description>VMWare Virtual Center vpxd info message.</description>
</rule>
<!-- Authentication messages. -->
<rule id="19204" level="3">
<if_sid>19203</if_sid>
<match>[Auth]: User</match>
<description>VMWare Virtual Center vpxd authentication success.</description>
<group>authentication_success,</group>
</rule>
<rule id="19205" level="5">
<if_sid>19203</if_sid>
<match>Unable to log on locally as</match>
<description>VMWare Virtual Center vpxd NETWORK-style logon.</description>
<group>authentication_failed,</group>
</rule>
<!-- SSL errors. -->
<rule id="19206" level="5">
<if_sid>19201</if_sid>
<match>SSLVerifyCertAgainstSystemStore</match>
<description>VMWare Virtual Center vpxd SSL error.</description>
<group>system_error,</group>
</rule>
</group> <!-- VMWare Virtual Center vpxd -->
<!-- EOF -->
--
Saludos de #linux, tu canal comunitario.