Thanks Guys, Helps a great deal. Sorry, I was mistaken, the "\(\d+\)" did match this line, I just had to scroll down in my email window to find it: Aug 19 01:29:20 10.1.0.2 115962: Aug 19 06:29:19.883 UTC: %SEC-6-IPACCESSLOGP: list I1-In denied tcp 84.123.112.60(3389) -> 199.133.160.228(5900), 1 packet Its way cool how OSSEC packs several alert emails into one :-) Thanks again. Hope you add these gems to the manual. Randy
****************************************** Randy Bradley IT Specialist USDA ARS MARC Clay Center, NE 68933 phone: 402-762-4156 ****************************************** |
- [ossec-list] Creating Rule Groups gentuxx
- [ossec-list] Re: Creating Rule Groups Daniel Cid
- [ossec-list] Re: Creating Rule Groups gentuxx
- [ossec-list] Re: Creating Rule Groups gentuxx
- [ossec-list] Re: Creating Rule Groups Randy Bradley
- [ossec-list] Re: Creating Rule Groups gentuxx
- [ossec-list] Re: Creating Rule Groups Meir Michanie
- [ossec-list] Re: Creating Rule Groups Daniel Cid
- [ossec-list] Re: Creating Rule Groups Randy Bradley
- [ossec-list] Re: Creating Rule Groups gentuxx
