OpenVPN LDAP Bind Failure · match LDAP bind failed:


Description

OpenVPN LDAP Bind Failure: $(ldap_data.error_message)

Query · wazuh

match="^LDAP bind failed:"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. decoded_as=openvpn
  2. 81805 OpenVPN LDAP Bind Failure · match LDAP bind failed: refinement level 5 this rule
    match="^LDAP bind failed:"

Rule dependencies

Depends on

Raw source OpenVPN LDAP Bind Failure · match LDAP bind failed: · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="81805" level="5">
    <if_sid>81800</if_sid>
    <match>^LDAP bind failed:</match>
    <description>OpenVPN LDAP Bind Failure: $(ldap_data.error_message)</description>
    <group>pci_dss_10.2.5,gpg13_7.1,gpg13_7.2,gdpr_IV_32.2,hipaa_164.312.b,nist_800_53_AU.14,nist_800_53_AC.7</group>
  </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.