Closed davidjiglesias closed 6 months ago
Installation
~While working on the issue face a problem on the vagrant after which I couldn't finish the procedure: While working on a solution I'm asking for aws instances.~
Found a way of continuing through the virtualbox machines, will continue that way.
Modify ossec.conf
<localfile>
<location>Microsoft-Windows-Sysmon/Operational</location>
<log_format>eventchannel</log_format>
</localfile>
After enabling logall
and sending Windows Events, we can see the logs immediately:
LGTM!!
End-to-End (E2E) Testing Guideline
Release testing
objective andVery high
priority. Communicate these to the team and QA via the c-release Slack channel.For the conclusions and the issue testing and updates, use the following legend:
Status legend
Issue delivery and completion
review_assignee
field in the project. The reviewer must then review the test steps and results. Ensure that all iteration cycles are completed by Feb 28, 2024 date (issue must be inPending final review
status) and notify the QA team via Slack using the c-release channel.Deployment requirements
Test description
Test that Windows data collection works out of the box. Check that for the same Windows events, the alert rule IDs are the same as in the previous version. Test the following blog post: https://wazuh.com/blog/emulation-of-attck-techniques-and-detection-with-wazuh/ Install sysmon and create Wazuh rules as mentioned, to ensure that everything works as intended in the blog post (use the current release under test instead of 4.2.0) Use the blogpost as a mere guide for testing some Windows events and the use cases, do not report issues with the blogpost itself, outdated commands, etc.
Known issues
Conclusions
I have met the end of the test without any possible issue.
Feedback
We value your feedback. Please provide insights on your testing experience.
Reviewers validation
The criteria for completing this task is based on the validation of the conclusions and the test results by all reviewers.
All the checkboxes below must be marked in order to close this issue.