I'm sure this has been asked before, so please excuse my dual asking of the 
question (I was unable to find a good answer via google).

Is there any way to filter out specific regex from a localfile (syslog) easily?

Basically, I have some default window agents setup, and am being hit with the 
"broadcast" traffic.

I'd like to take the default of:

<ossec_config>
  <localfile>
    <location>C:\Windows\pfirewall.log</location>
    <log_format>syslog</log_format>
  </localfile>
</ossec_config>


And easily filter out, say the following -> sender host 10.10.10.15 to 
255.255.255.255 destination UDP port 138 but get the rest of the window 
firewall log entries.

If anyone could point me in the right direction, I'd be grateful.

                Thanks

                                David

Reply via email to