Can you supply the full rule and an example log file so we can test and confirm 
what you are seeing.  

Thank you

> On Jun 7, 2014, at 10:16 AM, "James MacLean" <[email protected]> wrote:
> 
> My local_rules.xml had 2 regex expresions using \$. Both failed with 2.8. 
> 
> Replacing them with \. allowed ossec to start.
> 
> Is there a new expression to match $ in alerts as of 2.8?
> 
> Thanks,
> JES
> -- 
> 
> --- 
> You received this message because you are subscribed to the Google Groups 
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected].
> For more options, visit https://groups.google.com/d/optout.

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to