Here are the results from that search:
root@graylog01:/var/log# curl -XGET 'localhost:9200/graylog*/_search?q="salt.loaded.int.module.cmdmo"?&pretty'
{
"took" : 1076,
"timed_out" : false,
"_shards" : {
"total" : 12,
"successful" : 12,
"failed" : 0
},
"hits" : {
"total" : 43943913,
"max_score" : 0.033698954,
"hits" : [ {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e73d972-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:13 portaonelab04 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/libexec/nagios/portaone/ntp.pl --offset_c 1 --hosts pool.ntp.org",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:14.000",
"Location" : "(portaonelab04.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e73d974-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:13 portaonelab04 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/libexec/nagios/portaone/disk_health.pl -skip_bbu=N -skip_wcp=N -temp_w=40 -temp_c=45 -pending_w=0 -pending_c=0 -wearout_w=85 -wearout_c=95 -error_w=0 -error_c=20 -other_error_w=0 -other_error_c=20",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:14.000",
"Location" : "(portaonelab04.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e742797-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:14 portaonelab01 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/libexec/nagios/portaone/watchdog.pl -service=cron,syslog,sshd,chrony -mail=1 -sip=0 -log=0 -xdrm=0",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ "58012b0db2ab7c7cacd2f466" ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:15.000",
"Location" : "(portaonelab01.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e742793-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:15 poconfig01 sshd[48236]: Accepted publickey for porta-one from 10.59.10.19 port 39650 ssh2: DSA 8f:b3:11:8a:e0:6b:54:30:bc:8a:4d:ce:67:35:3d:30",
"device_product" : "OSSEC HIDS",
"src" : "10.59.10.19",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5715, LOW] SSHD authentication success.",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "porta-one",
"event_class_id" : "5715",
"severity_number" : 3,
"name" : "SSHD authentication success.",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:15.000",
"Location" : "(poconfig01.chi5.prlss.net)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e744ea4-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:14 portaonelab01 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/libexec/nagios/portaone/disk_health.pl -skip_bbu=N -skip_wcp=N -temp_w=40 -temp_c=45 -pending_w=0 -pending_c=0 -wearout_w=85 -wearout_c=95 -error_w=0 -error_c=20 -other_error_w=0 -other_error_c=20",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ "58012b0db2ab7c7cacd2f466" ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:15.000",
"Location" : "(portaonelab01.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e744ea5-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:14 portaonelab01 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/home/porta-billing/scripts/disconnector_monitor.pl -delay_c=10 -delay_w=5 -pending_c=100 -pending_w=50",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ "58012b0db2ab7c7cacd2f466" ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:15.000",
"Location" : "(portaonelab01.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e7475b0-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:15 portaonelab02 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/libexec/nagios/portaone/watchdog.pl -service=cron,syslog,sshd,chrony,task-queue,converter-queue,g729-converter-queue,billsoft,kairosdb,gearmand,pum-mwid,pum-mfd,dbmail-imapd,gearman_worker -mail=1 -sip=1 -log=0 -xdrm=1",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:16.000",
"Location" : "(portaonelab02.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e7475b1-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:14 portaonelab03 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/libexec/nagios/portaone/netif.pl -errors_w=0.1% -errors_c=1% -exclude=none -ignore_drops=none",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:15.000",
"Location" : "(portaonelab03.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e7475b6-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:15 portaonelab02 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/usr/libexec/nagios/portaone/ntp.pl --offset_c 1 --hosts pool.ntp.org",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:16.000",
"Location" : "(portaonelab02.chi5.prlss.int)"
}
}, {
"_index" : "graylog_2",
"_type" : "message",
"_id" : "9e74c3d5-4877-11e7-89eb-005056bb66df",
"_score" : 0.033698954,
"_source" : {
"device_version" : "v2.8",
"severity" : "LOW",
"msg" : "Jun 3 16:16:15 portaonelab02 sudo: nagios : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/home/porta-configurator/bin/crontabs-mon.pl",
"device_product" : "OSSEC HIDS",
"gl2_remote_ip" : "172.16.159.203",
"gl2_remote_port" : 35119,
"streams" : [ ],
"source" : "ossec01",
"message" : "OSSEC HIDS: [5402, LOW] Successful sudo to ROOT executed",
"gl2_source_input" : "57fbc518b2ab7c425214314d",
"dvc" : "ossec01",
"suser" : "nagios",
"event_class_id" : "5402",
"severity_number" : 3,
"name" : "Successful sudo to ROOT executed",
"gl2_source_node" : "06c5aaf1-30e9-4546-9dbd-474a752bf2dd",
"device_vendor" : "Trend Micro Inc.",
"timestamp" : "2017-06-03 16:16:16.000",
"Location" : "(portaonelab02.chi5.prlss.int)"
}
} ]
}
}