On Sun, Apr 26, 2009 at 4:56 AM, Andre Pawlowski <[email protected]> wrote: > > Hey guys, > > I have the following problem. I used ossec on my servers and the rule > 1002 "Unknown problem somewhere in the system." fires all the time. I > know this log entries and want to stop ossec from sending me mails when > this patterns come along. The rule uses a bad word list and I can delete > the words fire the rule. But I want unknown log entries with words like > "error" or "failure" send to me too. > > So, is it possible to exclude a (for example regex) pattern from a rule? > The log entries are some of these: > > Apr 25 23:31:55 servername smartd[7657]: Device: /dev/hda, SMART Prefailure > Attribute: 1 Raw_Read_Error_Rate changed from 88 to 87 > > or > > Apr 25 10:33:40 servername HORDE[14046]: [horde] Error retrieving session > data (id = 97c2565csadf126asdf9deacd): Lock wait timeout exceeded; try > restarting transaction [pid 14046 on line 144 of > "/dir/to/horde/lib/Horde/SessionHandler/mysql.php"] > > I hope you can help me. Thanks in advance > > -- > > Andre Pawlowski > > ------------------------------------------------------------------- > > If you could be God's worst enemy or nothing, which would you choose? > -Chuck Palahniuk > >
Create local rules that match on the entries you want to ignore and set them to a low level (level="0"). You may need to include "<if_sid>1002</if_sid>" in some of these rules to get them to work instead of ossec firing 1002 alerts off instead. dan
