I wrote a rule
<group name="local,syslog,">
<rule id="101000" level="0" noalert="1">
<decoded_as>adsl</decoded_as>
<description>Grouping for the adsl rules.</description>
</rule>
<rule id="101001" level="8">
<if_sid>101000</if_sid>
<description>Monitor adsl line down</description>
<match>ADSL line is down</match>
</rule>
<rule id="101002" level="8">
<if_sid>101000</if_sid>
<description>Monitor adsl line up</description>
<match>ADSL line is up</match>
</rule>
</group> <!-- SYSLOG,LOCAL -->
to check for log entries ...
Apr 7 16:57:02 thecla2 kernel: ATM dev 0: ADSL line is down
Apr 7 16:57:03 thecla2 kernel: ATM dev 0: ADSL line is synchronising
Apr 7 16:57:43 thecla2 kernel: ATM dev 0: ADSL line is up (2656 kb/s
down | 448 kb/s up)
However it does seem to trigger, well at least generate an email.
It gets loaded ...
2007/04/04 23:44:34 ossec-analysisd: Reading rules file:
'adsl_rules.xml'
Is it just me or is the documentation a bit sparse?
Thanks Martin West