Yes; try cdb lists 
http://www.ossec.net/doc/manual/rules-decoders/rule-lists.html

Sent from my iPhone

On Nov 19, 2010, at 6:50 PM, [email protected] wrote:

> 
> I'm trying to write a rule to match on a regex, but only if it comes from 
> certain hosts. 
> 
> It's easy enough to do this: 
> 
>   <rule id="102001" level="2"> 
>     <if_sid>1002</if_sid> 
>     <srcip>10.10.10.10</srcip> 
>     <srcip>10.10.10.20</srcip> 
>     <regex>[\d+]: this is a false positive </regex> 
>     <options>no_email_alert</options> 
>     <description>Don't send email alerts on these bogus false 
> positives</description> 
>   </rule> 
> 
> if there's only one or two hosts.  But if there are lots of host IPs that 
> happen to match 
> a pattern, it gets cumbersome.  What' I'd like to do is something like: 
> 
> <srcip_regex>10.10.1\d.\d0</srcip_regex> 
> 
> Is there another way to do this? 
> 
> Dean Takemori
> Systems Support Supervisor
> TD Food Group
> [email protected]

Reply via email to