This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
OK
  • RSA.com
  • Products
    • Archer®
      • Archer®
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Archer® Exchange
      • Training
      • Upcoming Events
      • Videos
    • RSA® Fraud & Risk Intelligence Suite
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Web Threat Detection
      • Upcoming Events
      • Videos
    • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Cloud
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Patch Content
      • Videos
    • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication Mobile SDK
      • Advisories
      • Events
      • Ideas
      • Knowledge Base
      • Request Access
      • Training
    • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication for eCommerce
      • RSA® Adaptive Authentication for eCommerce
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® FraudAction Services
      • RSA® FraudAction Services
      • Advisories
      • Discussions
      • Documentation
      • Ideas
      • Videos
    • RSA® Web Threat Detection
      • RSA® Web Threat Detection
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Videos
    • RSA NetWitness® Platform
      • RSA NetWitness® Platform
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA NetWitness® Detect AI
      • RSA NetWitness® Detect AI
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Investigator
      • RSA NetWitness® Investigator
      • Documentation
      • Download the Client
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Orchestrator
      • RSA NetWitness® Orchestrator
      • Overview
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA SecurID® Suite
      • RSA SecurID® Suite
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Knowledge Base
      • Ideas
      • Integrations
      • Training
      • Videos
    • RSA® Identity Governance & Lifecycle
      • RSA® Identity Governance & Lifecycle
      • Advisories
      • Blog
      • Community Exchange
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA SecurID® Access
      • RSA SecurID® Access
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • Other RSA® Products
      • Other RSA® Products
      • RSA® Access Manager
      • RSA® Data Loss Prevention
      • RSA® Digital Certificate Solutions
      • RSA enVision®
      • RSA® Federated Identity Manager
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
  • Resources
    • Advisories
      • Product Advisories on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Hosted
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Product Advisories
    • Blogs
      • Blogs on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Blogs on RSA Link
    • Discussion Forums
      • Discussion Forums
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Discussion Forums on RSA Link
    • Documentation
      • Product Documentation
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Downloads
      • Product Downloads
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Downloads on RSA Link
    • Ideas
      • Idea Exchange
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Knowledge Base
      • Knowledge Base
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Knowledge Base Pages on RSA Link
    • Upcoming Events on RSA Link
      • Upcoming Events
    • Videos
      • Videos on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise
      • RSA® Adaptive Authentication On-Premise (Cassandra)
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Videos on RSA Link
  • Support
    • RSA Link Support
      • RSA Link Support
      • News & Announcements
      • Getting Started
      • Support Forum
      • Support Knowledge Base
      • Ideas & Suggestions
    • RSA Product Support
      • RSA Product Support
      • General Security Advisories and Statements
      • Product Life Cycle
      • Support Information
      •  
      •  
      •  
      •  
      •  
  • RSA Ready
  • RSA University
    • Certification Program
      • Certification Program
    • Course Catalogs
      • Course Catalogs
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • On-Demand Subscriptions
      • On-Demand Subscriptions
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • Product Training
      • Product Training
      • Archer®
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Identity Governance & Lifecycle
      • RSA NeWitness® Platform
      • RSA SecurID® Access
    • Student Resources
      • Student Resources
      • Access On-Demand Learning
      • Access Virtual Labs
      • Contact RSA University
      • Enrollments & Transcripts
      • Frequently Asked Questions
      • Getting Started
      • Learning Modalities
      • Payments & Cancellations
      • Private Training
      • Training Center Locations
      • Training Credits
      • YouTube Channel
    • Upcoming Events
      • Upcoming Events
      • Full Calendar
      • Conferences
      • Live Classroom Training
      • Live Virtual Classroom Training
      • Webinars
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

Visit the Known Issues dashboard if you are experiencing issues on RSA Link

View Dashboard

RSA enVision® Discussions

Browse the RSA enVision discussion board to get product help and collaborate with other users of RSA enVision.
  • RSA Link
  • :
  • Products
  • :
  • Other RSA Products
  • :
  • RSA enVision
  • :
  • Discussions
  • :
  • Security_560_Security Events for FileAudting / GPO...
  • Options
    • Subscribe to RSS Feed
    • Mark Topic as New
    • Mark Topic as Read
    • Float this Topic for Current User
    • Bookmark
    • Subscribe
    • Mute
    • Printer Friendly Page
RSAAdmin
RSAAdmin Beginner
Beginner
‎2008-04-16 03:55 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Security_560_Security Events for FileAudting / GPOAuditing / Etc

Version 3.7.0 build 0169

 

I hope this helps . . . it took me a few to get to the bottom of this one.

 

My main objective was to audit Microsoft AD GPO addtions, modifications, and deletions.  For the life of me I could not find the actual file being audited in the parsed data anywhere.  I could see the raw event being captured with the data I needed via the MessageView . . . but running reports, query, and alerts would not show the file being audited in the Misc Name field (which is where it is supposed to be).

 

I found the following to be true . . . it took me a bit of digging to get this point. 

 

The XML for the winevent_nic was not parsing the data properly.  The data field misc_name was being used twice in the same content string . . . which means the latter use was overwriting the first.   Look at message Security_560_Security:02 for example . . . Object Name: <misc_name> is the first instance and then later in the content string Image File Name: <misc_name> . . . the latter value kept showing up in Alerts, Query, and Reports.

 

SOLUTION:  Rename the data field that was mapping to Image File Name.  I created two new messages to get the content I needed . . . mapping Image File Name to  a bogus_field.  The two messages I used to solve my issue, Security_560_Security:04 and Security_560_Security:05, can be seen below . . . 05 accounts for a random space in the incoming MS message. 

 

<MESSAGE 
        level="4"  
        parse="1"  
        parsedefvalue="1"  
        tableid="5"  
        id1="Security_560_Security:04"  
        id2="Security_560_Security"  
        eventcategory="1401010000"  
        summary="NIC_B_WINDOWS;sumtype=11;|NIC_B_WINDOWS;key=event_computer;sumtype=12;|NIC_B_WINDOWS;key=event_type;sumtype=13;|NIC_B_WINDOWS;key=category;sumtype=14;|NIC_B_CATEGORIES;sumtype=denied_in;|NIC_B_CATEGORIES;subkey=event_log;sumtype=connection;"        
        content="&lt;@utcstamp:*UTC($MSG,'%B %D %N:%U:%O %W',datetime)&gt;&lt;@category:smileysurprised:bject_Access&gt; &lt;@event_user:*RMQ(event_user)&gt;&lt;event_log&gt;,&lt;linenum&gt;,&lt;day&gt; &lt;datetime&gt;,&lt;event_id&gt;,&lt;event_source&gt;,&lt;event_user&gt;,&lt;event_type&gt;,&lt;event_computer&gt;,&lt;category&gt;,&lt;data&gt;,&lt;event_description&gt;:&lt;space&gt;Object Server: &lt;obj_server&gt;Object Type: &lt;obj_type&gt;Object Name: &lt;misc_name&gt;Handle ID: &lt;handle_id&gt;Operation ID: &lt;operation_id&gt;Process ID: &lt;process&gt;Image File Name: &lt;bogus_field&gt;Primary User Name: &lt;username&gt;Primary Domain: &lt;domain&gt;Primary Logon ID: &lt;logon_id&gt;Client User Name: &lt;c_user_name&gt;Client Domain: &lt;c_domain&gt;Client Logon ID: &lt;c_logon_id&gt;Accesses &lt;accesses&gt;Privileges &lt;privileges&gt;Restricted Sid Count: &lt;fld4&gt;Access Mask: &lt;peer_id&gt;" />
<MESSAGE 
        level="4"  
        parse="1"  
        parsedefvalue="1"  
        tableid="5"  
        id1="Security_560_Security:05"  
        id2="Security_560_Security"  
        eventcategory="1401010000"  
        summary="NIC_B_WINDOWS;sumtype=11;|NIC_B_WINDOWS;key=event_computer;sumtype=12;|NIC_B_WINDOWS;key=event_type;sumtype=13;|NIC_B_WINDOWS;key=category;sumtype=14;|NIC_B_CATEGORIES;sumtype=denied_in;|NIC_B_CATEGORIES;subkey=event_log;sumtype=connection;"        
        content="&lt;@utcstamp:*UTC($MSG,'%B %D %N:%U:%O %W',datetime)&gt;&lt;@category:smileysurprised:bject_Access&gt; &lt;@event_user:*RMQ(event_user)&gt;&lt;event_log&gt;,&lt;linenum&gt;,&lt;day&gt; &lt;datetime&gt;,&lt;event_id&gt;,&lt;event_source&gt;,&lt;event_user&gt;,&lt;event_type&gt;,&lt;event_computer&gt;,&lt;category&gt;,&lt;data&gt;,&lt;event_description&gt;: &lt;space&gt; Object Server: &lt;obj_server&gt; Object Type: &lt;obj_type&gt; Object Name: &lt;misc_name&gt; Handle ID: &lt;handle_id&gt; Operation ID: &lt;operation_id&gt; Process ID: &lt;process&gt; Image File Name: &lt;bogus_field&gt; Primary User Name: &lt;username&gt; Primary Domain: &lt;domain&gt; Primary Logon ID: &lt;logon_id&gt; Client User Name: &lt;c_user_name&gt; Client Domain: &lt;c_domain&gt; Client Logon ID: &lt;c_logon_id&gt; Accesses &lt;accesses&gt; Privileges &lt;privileges&gt; Restricted Sid Count: &lt;fld4&gt; " />
 

  • Tags:
  • Community Thread
  • Discussion
  • enVision
  • Forum Thread
  • RSA enVision
0 Likes
Share
Reply
  • All forum topics
  • Previous Topic
  • Next Topic
7 Replies
RSAAdmin
RSAAdmin Beginner
Beginner
‎2008-09-03 11:02 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

I was having a similar problem and submitted it as a bug to support.  They had a new XML for me that took care of it.

 

Sometimes it's worth a support case to fix something that should be working rather than having to go through all that trouble to do it.

 

That said, great job!!

0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to RSAAdmin
‎2008-09-03 11:05 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Believe me . . . I had support cases open on this one.
0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
‎2008-09-03 11:06 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Maybe they fixed it based on your solution :smileyvery-happy:
0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to RSAAdmin
‎2008-09-05 02:21 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Yeah, since we're on the topic of winevent_nicmsg.xml I recall I ran across a very similar issue just the other day  (yes I reported it by opening a case), this one was specific to the Security_566_Security:02 message ID.   Turns out a trailing colon is missing from "accesses". 

 

Instead of reading      Accesses&lt;accesses&gt;
It should really read    Accesses:&lt;accesses&gt;

 

Sounds very minimal, but its amazing what that extra : will do when you're trying to hard code exact filter statements against the Accesses field in correlation rules.  I had to learn to put ": " in front of all of them to accommodate for the .xml. 


I'm on version 3.5.2 and my current winevent_nicmsg.xml states:

<MESSAGE
  level="4"
  parse="1"
  parsedefvalue="1"
  tableid="5"
  id1="Security_566_Security:02"
  id2="Security_566_Security"
  eventcategory="1206000000"
  summary="NIC_B_WINDOWS;sumtype=11;|NIC_B_WINDOWS;key=event_computer;sumtype=12;|NIC_B_WINDOWS;key=event_type;sumtype=13;|NIC_B_WINDOWS;key=category;sumtype=14;|NIC_B_CATEGORIES;sumtype=denied_in;|NIC_B_CATEGORIES;subkey=event_log;sumtype=connection;"  
  content="&lt;@utcstamp:*UTC($MSG,'%B %D %N:%U:%O %W',datetime)&gt;&lt;@category:smileysurprised:bject_Access&gt; &lt;@event_user:*RMQ(event_user)&gt;&lt;event_log&gt;,&lt;linenum&gt;,&lt;day&gt; &lt;datetime&gt;,&lt;event_id&gt;,&lt;event_source&gt;,&lt;event_user&gt;,&lt;event_type&gt;,&lt;event_computer&gt;,&lt;category&gt;,&lt;data&gt;,&lt;event_description&gt;: &lt;space&gt; Operation Type: &lt;type&gt;Object Type: &lt;obj_type&gt;Object Name: &lt;misc_name&gt;Handle ID: &lt;handle_id&gt;Primary User Name: &lt;username&gt;Primary Domain: &lt;domain&gt;Primary Logon ID: &lt;logon_id&gt;Client User Name: &lt;c_user_name&gt;Client Domain: &lt;c_domain&gt;Client Logon ID: &lt;c_logon_id&gt;Accesses&lt;accesses&gt;Properties: &lt;fld5&gt;Additional Info: &lt;info1&gt;Additional Info2: &lt;info2&gt;Access Mask: &lt;peer_id&gt;" />

 

 

cheers,

ryan

0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to RSAAdmin
‎2008-09-29 11:22 AM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Update:   I got a response back on my case that this has been resolved.  I think, the same problem was found across 4 or 5 other winevent_nic event IDs.    I'm pretty sure this has been fixed in the recent Device Update package that came out last week.

 

 

0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to RSAAdmin
‎2008-10-27 06:14 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Boy, I'm glad I checked the forums on this - I was just in the process of developing a report based on file auditing to determine who deleted a file, and noticed the same thing - the Object Name was listed in the message viewer, but not in the query.  I had not yet downloaded the Device Update package - just did so, and it sounds like that should take care of my issue as well.  If not, thanks for the information on the messages!
0 Likes
Share
Reply
RSAAdmin
RSAAdmin Beginner
Beginner
In response to RSAAdmin
‎2008-10-31 05:08 PM
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

I just checked the documentation on the latest device update package - no windows events at all.  Sounds like I will have to call them about getting a new .xml for windows events.
0 Likes
Share
Reply
Powered by Khoros
  • Products
  • Resources
  • Solutions
  • RSA University
  • Support
  • RSA Labs
  • RSA Ready
  • About RSA Link
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
© 2020 RSA Security LLC or its affiliates.
All rights reserved.