Conversation
The address step splits src and dst only as ip:port:interface. The grok step writes nothing unless every pattern matches and the filter then deletes the value, so ip:port (VPN negotiation events) and ip::interface (user logins) lose their address. When fw_action is the last key, the rescue grok cannot bound it and the fallback rename reads log.fwaction, while go-sdk v1.1.35 and later keep the underscore, so those events get no action and no outcome. Events whose firewall action is NA get no outcome at all, and the CEF header step captures its fields with a lone lazy pattern, which the grok step rejects. Each address shape now has its own step, and the original value is deleted only after an address was read. A fallback reads fw_action under both spellings. Events without a firewall decision get an outcome from the meaning of their message: allowed logins and completed IKEv2 negotiations give success, as does Connection Closed when bytes came back; bad credentials, RADIUS, LDAP, XAUTH and SSO failures and failed IKE negotiations give failure; policy and zone refusals give denied. The CEF header fields use a non-empty pattern. The administrator authentication-failure rule counted "Administrator login allowed" (29) as a failure and, through its message branch, SSO probe failures and policy denials. It now counts logins denied due to bad credentials with a failure outcome, its history counts failures from the same address, and alerts group by address, so a password spray is one alert instead of one per user name. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Grouping by address only nests repeats: every attempt that passes the history check still creates a child alert. On the busiest day in the last week one deployment had 41,227 bad-credential denials from 41 addresses, which would create 40,756 alerts. Deduplicating by address creates 15 and keeps one alert per source for seven days. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
On the current EventProcessor, the SonicWall filter misses most outcomes and many source addresses:
srcanddstonly in the formip:port:interface. The grok step writes nothing unless every pattern matches, and the filter then deletes the original value. Soip:port(used by VPN negotiation events) andip::interface(used by user login events) lose their address completely. On one deployment this was most of the traffic.fw_actionis the last key on the line, the rescue grok cannot bound it, and the fallback rename still readslog.fwaction. go-sdkv1.1.35and later keep the underscore (log.fw_action), so those events get noactionand no outcome. That was about a quarter of drops on one deployment and most drops on another.fw_actiongives an outcome (forwardgivessuccess,dropgivesdenied). Events whose firewall action isNAget none, including failed logins, failed or refused VPN negotiations, allowed logins and closed connections.{{.data}}template alone. The grok step rejects an empty match, so the step never writes.The administrator authentication-failure rule counts event 29, which is "Administrator login allowed", as a failure. Its message branch also matches SSO probe failures and policy denials, and its history counts any event from the same address. Grouping by address and user turns a password spray into one alert per user name, and grouping only nests repeats, so every attempt that passes the history check still creates an alert.
Change
ip:port:interface,ip:portandip::interface. The original value is deleted only after an address was read, and a bare value moves toorigin.iportarget.iponly when it is an IP address.fw_actionunder both spellings when the rescue does not.success: logins allowed (29, 31, 236, 237, 238, 1080), "IKEv2 Authentication successful" (942), "IKEv2 negotiation complete" (978), and "Connection Closed" (537) when bytes came back.failure: logins denied due to bad credentials (32, 33, 200), a timed-out pending login (34), XAUTH, RADIUS and LDAP failures (140, 243, 244, 746, 747), an expired password (1035), a failed SSO probe (1117), and failed IKE negotiations (402, 658, 953, 967, 1305).denied: "User login denied - not allowed by Policy rule" (986) and "SSLVPN service is not allowed on " (1079).fw_actionstill takes precedence.sonicwall_admin_auth_failures(v2.2.0): counts logins denied due to bad credentials that carryfailure. Its history counts failures from the same address, and alerts are deduplicated by address, which keeps one alert per source for seven days.Validation
All results use the latest versions: EventProcessor
8a3ade7, with every parser and rule plugin on go-sdkv1.1.36, andv11d2479c1a.ip:port, a login failure withip::interface, a source without an address, a bare source address, and an allowed WAN login. The unchanged filter passed 0/6. This branch passed 6/6, including the CEF header fields.v1.1.36on this branch's output for the 42 real records. The current condition matched 9: the 5 logins denied due to bad credentials, plus 2 logins denied by policy and 2 failed SSO probes, which are not credential guessing. The new condition matched exactly the 5. The fullplugins/alertssuite passes.Production context
Limits
msg,usr,noteand the rest) are deleted before their rescue runs, so they are lost when they are the last key on the line. In 8,000 sampled records onlyuuidwas ever last (91 records), which loses the event UUID; this change leaves that behavior as it is.🤖 Generated with Claude Code