From a226ec0301b0cdcd6fe971df6abb3edf374dc352 Mon Sep 17 00:00:00 2001 From: Ricardo Valdes Date: Wed, 16 Sep 2026 20:34:31 -0400 Subject: [PATCH] fix: align IBM AIX filter and rule contracts --- filters/audits/ibm-aix.md | 40 +++++++++++ filters/ibm/ibm_aix.yml | 72 +++++++++++++++++-- .../testdata/filter-contracts/ibm-aix.json | 50 +++++++++++++ 3 files changed, 156 insertions(+), 6 deletions(-) create mode 100644 filters/audits/ibm-aix.md create mode 100644 plugins/alerts/testdata/filter-contracts/ibm-aix.json diff --git a/filters/audits/ibm-aix.md b/filters/audits/ibm-aix.md new file mode 100644 index 000000000..95823b606 --- /dev/null +++ b/filters/audits/ibm-aix.md @@ -0,0 +1,40 @@ +# IBM AIX normalization and rule review + +Fix grok field spelling and origin.host; validate IP/protocol values. + +This draft targets UTMStack `v11`. It contains 1 filter changes +and 0 rule changes for this technology only. Review covered +1 filter configurations and 10 matching shipped rule files. +Unchanged rules are listed in the regression manifest; they are not duplicated in the diff. + +## Contract and validation + +- Compared exact standard names/types with go-sdk v1.1.31 and the supplied UTMStack dictionaries. +- Checked documented pipeline ordering, rename/move behavior, open vendor log fields, + event-side versus alert-side fields, and surviving fields used by affected rule predicates/history/grouping. +- Strict SDK configuration decoding and actual CEL compilation pass for this scope. +- 2 synthetic normalization cases pass, including SDK Event conversion and any + trigger predicate assertions recorded in the manifest. +- The scoped alerts module tests and `git diff --check` pass with the shared contract runner applied. + +The shared alert-contract PR supplies the reusable Go runner for the manifest in +`plugins/alerts/testdata/filter-contracts/ibm-aix.json`. Apply that support before running `go test ./...` in `plugins/alerts`. + +The model starts from synthetic extraction results. It does not run complex grok, +JSON/KV/XML/CSV extraction, time conversion, dynamic plugins, historical OpenSearch +queries, or the closed EventProcessor. Raw vendor logs and resulting alerts must +still be checked in staging before rollout. No customer false-positive reduction +has been measured and no production rollout is included. + + + +## References + +- [SDK schema](https://github.com/threatwinds/go-sdk/blob/v1.1.31/plugins/plugins.proto) +- [Filter steps](https://github.com/threatwinds/go-sdk/wiki/Filter-Steps-Reference) +- [Standard event schema](https://github.com/threatwinds/go-sdk/wiki/Standard-Event-Schema) +- [Rule implementation](https://github.com/threatwinds/go-sdk/wiki/Implementing-Rules) + +`afterEvents`, empty noncapturing grok names, supported numeric strings, and custom +`log.*` fields are accepted. Existing textual protocol casing and vendor action names +are preserved unless a concrete consumer mismatch requires correction. diff --git a/filters/ibm/ibm_aix.yml b/filters/ibm/ibm_aix.yml index 90c9c0bbb..c81a78bec 100644 --- a/filters/ibm/ibm_aix.yml +++ b/filters/ibm/ibm_aix.yml @@ -46,9 +46,9 @@ pipeline: # .......................................................................# - grok: patterns: - - fildName: log.irrelevant + - fieldName: log.irrelevant pattern: 'Message(\s)forwarded(\s)from' - - fieldName: from.host + - fieldName: origin.host pattern: '{{.data}}(\:)' - fieldName: log.msgAll pattern: '{{.greedy}}' @@ -60,7 +60,7 @@ pipeline: function: suffix substring: ":" fields: - - from.host + - origin.host #......................................................................# # Checking that the message contains TTY= or PWD= or COMMAND= or USER= @@ -549,8 +549,8 @@ pipeline: function: string params: key: actionResult - value: "failed" - where: 'exists("log.returnCode") && !equals("log.returnCode", "0")' + value: failure + where: exists("log.returnCode") && !equals("log.returnCode", "0") # Adding geolocation to origin.ip - dynamic: @@ -577,4 +577,64 @@ pipeline: - log.msgWithTTY - log.msgAll - log.msgInit - - log.restMsg \ No newline at end of file + - log.restMsg + + # Keep addresses in IP fields and retain other source values under log. + - rename: + from: + - origin.ip + to: log.unparsedOriginIp + where: exists("origin.ip") && (!(inCIDR("origin.ip","0.0.0.0/0") || inCIDR("origin.ip","::/0")) || oneOf("origin.ip",["0.0.0.0","::"])) + - add: + function: string + params: + key: protocol + value: ICMP + where: equals("protocol",1) + - add: + function: string + params: + key: protocol + value: TCP + where: equals("protocol",6) + - add: + function: string + params: + key: protocol + value: UDP + where: equals("protocol",17) + - add: + function: string + params: + key: protocol + value: GRE + where: equals("protocol",47) + - add: + function: string + params: + key: protocol + value: ESP + where: equals("protocol",50) + - add: + function: string + params: + key: protocol + value: AH + where: equals("protocol",51) + - add: + function: string + params: + key: protocol + value: ICMPV6 + where: equals("protocol",58) + - add: + function: string + params: + key: protocol + value: SCTP + where: equals("protocol",132) + - rename: + from: + - protocol + to: log.ipProtocolNumber + where: exists("protocol") && greaterOrEqual("protocol",0) diff --git a/plugins/alerts/testdata/filter-contracts/ibm-aix.json b/plugins/alerts/testdata/filter-contracts/ibm-aix.json new file mode 100644 index 000000000..2cc74f960 --- /dev/null +++ b/plugins/alerts/testdata/filter-contracts/ibm-aix.json @@ -0,0 +1,50 @@ +{ + "technology": "IBM AIX", + "filters": [ + "filters/ibm/ibm_aix.yml" + ], + "rules": [ + "rules/ibm/ibm_aix/aix_cron_persistence.yml", + "rules/ibm/ibm_aix/aix_hmc_access.yml", + "rules/ibm/ibm_aix/aix_nim_abuse.yml", + "rules/ibm/ibm_aix/aix_rootkit_detection.yml", + "rules/ibm/ibm_aix/aix_ssh_key_manipulation.yml", + "rules/ibm/ibm_aix/intrusion_detection_events.yml", + "rules/ibm/ibm_aix/security_audit_subsystem_alerts.yml", + "rules/ibm/ibm_aix/system_integrity_violations.yml", + "rules/ibm/ibm_aix/trusted_computing_base_events.yml", + "rules/ibm/ibm_aix/trusted_execution_violations.yml" + ], + "fixtures": [ + { + "name": "ibm_valid_source_ip", + "filter": "ibm/ibm_aix.yml", + "input": { + "origin": { + "ip": "2001:db8::7" + } + }, + "expected": { + "origin.ip": "2001:db8::7" + }, + "absent": [], + "rules": {} + }, + { + "name": "ibm_hostname_not_ip", + "filter": "ibm/ibm_aix.yml", + "input": { + "origin": { + "ip": "lab-host" + } + }, + "expected": { + "log.unparsedOriginIp": "lab-host" + }, + "absent": [ + "origin.ip" + ], + "rules": {} + } + ] +}