Re: [Simple-evcorr-users] "multi-line" and multi-file logs - out of box

2019-11-27 Thread Risto Vaarandi
hi Richard, Risto, thank you for your pre-analysis about multi-lines with regexp, and > also for suggestions about multi-files yet more sophisticated solution. > > My comments are also inline: > > st 27. 11. 2019 o 15:07 Risto Vaarandi > napísal(a): > >> hi Richard, >> > ... > >> In the current c

Re: [Simple-evcorr-users] "multi-line" and multi-file logs - out of box

2019-11-27 Thread Richard Ostrochovský
Risto, thank you for your pre-analysis about multi-lines with regexp, and also for suggestions about multi-files yet more sophisticated solution. My comments are also inline: st 27. 11. 2019 o 15:07 Risto Vaarandi napísal(a): > hi Richard, > ... > In the current code base, identifying the end

Re: [Simple-evcorr-users] "multi-line" and multi-file logs - out of box

2019-11-27 Thread Risto Vaarandi
hi Richard, these are interesting questions and you can find my comments inline: Hello guys, > > ... > > My question is, if you see, how some of this things could be accomplished > in more generic way, without special configurations of correlation rules. > It would be great having SEC supporting