Re: [Simple-evcorr-users] Newbie: Reporting on series of events

2010-12-01 Thread John P. Rouillard
In message <20101201193119.ga18...@esri.com>, Ray Van Dolson writes: >As an exercise to learn SEC, I'm trying to create a ruleset that will >report on clients sending more than X emails through our SMTP server in >Y amount of seconds. > >Basically I'm looking for the same "from" address, same mai

Re: [Simple-evcorr-users] Newbie: Reporting on series of events

2010-12-01 Thread Ray Van Dolson
On Wed, Dec 01, 2010 at 11:31:19AM -0800, Ray Van Dolson wrote: > As an exercise to learn SEC, I'm trying to create a ruleset that will > report on clients sending more than X emails through our SMTP server in > Y amount of seconds. > > Basically I'm looking for the same "from" address, same mail

[Simple-evcorr-users] Newbie: Reporting on series of events

2010-12-01 Thread Ray Van Dolson
As an exercise to learn SEC, I'm trying to create a ruleset that will report on clients sending more than X emails through our SMTP server in Y amount of seconds. Basically I'm looking for the same "from" address, same mail server and same client address (source IP) and if it occurs more than a ce

Re: [Simple-evcorr-users] query about sending data to SEC

2010-12-01 Thread Risto Vaarandi
On 12/01/2010 03:55 PM, M Haris Farooque wrote: > dear all, > > I have a very lame question to ask. > > how to send data to SEC from command line. The SEC is running as daemon. > I am using a FIFO (Pipe) from SEC to write some data instantly as log > data through pipe and its working fine but I l

[Simple-evcorr-users] query about sending data to SEC

2010-12-01 Thread M Haris Farooque
dear all, I have a very lame question to ask. how to send data to SEC from command line. The SEC is running as daemon. I am using a FIFO (Pipe) from SEC to write some data instantly as log data through pipe and its working fine but I like to use the same pipe to give an input back to SEC. Fol