Can you supply the full rule and an example log file so we can test and confirm what you are seeing.
Thank you > On Jun 7, 2014, at 10:16 AM, "James MacLean" <[email protected]> wrote: > > My local_rules.xml had 2 regex expresions using \$. Both failed with 2.8. > > Replacing them with \. allowed ossec to start. > > Is there a new expression to match $ in alerts as of 2.8? > > Thanks, > JES > -- > > --- > You received this message because you are subscribed to the Google Groups > "ossec-list" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > For more options, visit https://groups.google.com/d/optout. -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
