Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Juniper SRX] Add event.category and event.outcome to failed SSH login attempt #11834

Open
Oddly opened this issue Nov 22, 2024 · 1 comment
Open
Labels
Integration:juniper_srx Juniper SRX mapping/pipeline issue Team:Security-Deployment and Devices Deployment and Devices Security team [elastic/sec-deployment-and-devices]

Comments

@Oddly
Copy link

Oddly commented Nov 22, 2024

We have added Juniper switches to this integration, but we see no SIEM alerts on failed SSH attempts to this switch.
Looking at this integration, it seems like this can be added easily by doing the following steps.

Original event:

<37>1 2024-11-22T12:45:00.207+01:00 ams-edge-sw-003 sshd - SSHD_LOGIN_FAILED [[email protected] username="user1" source-address="192.168.0.3"]

This are the relevant fields as parsed by the integration:

juniper.srx.tag: SSHD_LOGIN_FAILED
source.user.name: user1

It seems to me that by filtering for "SSHD_LOGIN_FAILED" and then setting event.category (authentication) and event.outcome (failed ?) this can be easily added to existing SIEM alerts.

@jamiehynds jamiehynds added Integration:juniper_srx Juniper SRX Team:Security-Deployment and Devices Deployment and Devices Security team [elastic/sec-deployment-and-devices] labels Nov 22, 2024
@elasticmachine
Copy link

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Integration:juniper_srx Juniper SRX mapping/pipeline issue Team:Security-Deployment and Devices Deployment and Devices Security team [elastic/sec-deployment-and-devices]
Projects
None yet
Development

No branches or pull requests

3 participants