<rule id="100001" level="0">
    <if_sid>TRIGGERED_RULE_ID</if_sid>
    <match> sender host 10.10.10.15 to 255.255.255.255 destination UDP port 
138</match>
    <hostname>hostname_if_you_want_to_ignore_the_rule_just_for 
_that_host</hostname>
  </rule>

That should do it thought.

Xavi.
________________________________________
De: [email protected] [mailto:[email protected]] En nombre 
de Koski, David
Enviado el: dimecres, 21 / gener / 2009 15:15
Para: [email protected]
Asunto: [ossec-list] Logs

I'm sure this has been asked before, so please excuse my dual asking of the 
question (I was unable to find a good answer via google).

Is there any way to filter out specific regex from a localfile (syslog) easily?

Basically, I have some default window agents setup, and am being hit with the 
"broadcast" traffic.

I'd like to take the default of:

<ossec_config>
  <localfile>
    <location>C:\Windows\pfirewall.log</location>
    <log_format>syslog</log_format>
  </localfile>
</ossec_config>


And easily filter out, say the following -> sender host 10.10.10.15 to 
255.255.255.255 destination UDP port 138 but get the rest of the window 
firewall log entries.

If anyone could point me in the right direction, I'd be grateful.

                Thanks

                                David

Reply via email to