Hello Matt,

Tuesday, February 7, 2006, 6:27:25 PM, you wrote:

M> rule number, and I don't have the tools set up or the knowledge of grep
M> yet to do a piped query of Sniffer's logs to extract the spool file names.

http://www.baremetalsoft.com/ is a great grep'er for windows. In BSD I
always used ".*" to represent any number of characters, white space or
non, but that didn't seem to work with baregrep. That's why I was
trying to confirm with anyone on the list my regex of "Final\t828931"
was an accurate regex to find every message that 'finaled' on that
rule. I'm praying that I screwed up the expression and I don't have
22,055 messages held by that rule.

M> BTW, David, it is generally better not to hold or block on one single
M> test, especially one that automates such listings (despite whatever
M> safeguards there might be).

I know, shame on me. I guess I'm used to the days that we used to be
able to hold on sniffer alone. We have some safeguards in place now
and are transitioning our rule
methodologies but hadn't gotten to this one yet as this always
seems to hit back-burner.

This is also why I'd really like to see the content of the rule to see
how it made it passed our safeguards.

-- 
Best regards,
 David                            mailto:[EMAIL PROTECTED]



This E-Mail came from the Message Sniffer mailing list. For information and 
(un)subscription instructions go to 
http://www.sortmonster.com/MessageSniffer/Help/Help.html

Reply via email to