[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Matching questions
- To: <ossec-list@xxxxxxxxx>
- Subject: [ossec-list] Matching questions
- From: "Mark Haney" <mhaney@xxxxxxxxxxxxxxxx>
- Date: Mon, 05 Feb 2007 10:28:54 -0500
- Content-class: urn:content-classes:message
- Content-transfer-encoding: 7bit
- Importance: normal
- Priority: normal
- Thread-index: AcdJOlHq06t3n9UsTNyhDQlGyeH30Q==
Is it possible for me to set a rule up to trigger if a particular log
entry was NOT logged inside a time frame?
I want to test for the starting and stopping of a cron job. I have all
the rules in place for all the log entries it will generate, but I want
to be able to test to for the lack of a 'finished' log entry between say
midnight to 11:59pm. Is this possible? Or is there a work around to
make it possible?
--
Ita erat quando hic adveni.
Mark Haney
Sr. Systems Administrator
ERC Broadband
(828) 350-2415
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.