Snare agent on win2k3 box is sending syslog for an error 1000 (semaphore) - confirmed this is what WIndows is logging and Snare is capturing.
Event ID 1000
Description:
Faulting application w3wp.exe, version 6.0.3790.3959, faulting module unknown, version 0.0.0.0, fault address 0x01dd5c80.
When the event is parsed on MARS (4.3.6) the descriptive text from the event is lost (instead I get the binary values from the data field) - e.g.
0000: 41 70 70 6c 69 63 61 74
0008: 69 6f 6e 20 46 61 69 6c
0010: 75 72 65 20 20 77 33 77
0018: 70 2e 65 78 65 20 36 2e
0020: 30 2e 33 37 39 30 2e 33
0028: 39 35 39 20 69 6e 20 75
0030: 6e 6b 6e 6f 77 6e 20 30
0038: 2e 30 2e 30 2e 30 20 61
0040: 74 20 6f 66 66 73 65 74
0048: 20 30 31 64 64 35 63 38
0050: 30
This seems to be specific to this event - others are parsed properly on the MARS box (aside from some being truncated, which is another issue)
Anyone seen this? Any help appreciated...