<rule id="100001" level="0">
<if_sid>TRIGGERED_RULE_ID</if_sid>
<match> sender host 10.10.10.15 to 255.255.255.255 destination UDP port
138</match>
<hostname>hostname_if_you_want_to_ignore_the_rule_just_for
_that_host</hostname>
</rule>
That should do it thought.
Xavi.
________________________________________
De: [email protected] [mailto:[email protected]] En nombre
de Koski, David
Enviado el: dimecres, 21 / gener / 2009 15:15
Para: [email protected]
Asunto: [ossec-list] Logs
I'm sure this has been asked before, so please excuse my dual asking of the
question (I was unable to find a good answer via google).
Is there any way to filter out specific regex from a localfile (syslog) easily?
Basically, I have some default window agents setup, and am being hit with the
"broadcast" traffic.
I'd like to take the default of:
<ossec_config>
<localfile>
<location>C:\Windows\pfirewall.log</location>
<log_format>syslog</log_format>
</localfile>
</ossec_config>
And easily filter out, say the following -> sender host 10.10.10.15 to
255.255.255.255 destination UDP port 138 but get the rest of the window
firewall log entries.
If anyone could point me in the right direction, I'd be grateful.
Thanks
David