[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] Matching questions




Is it possible for me to set a rule up to trigger if a particular log entry was NOT logged inside a time frame?

I want to test for the starting and stopping of a cron job. I have all the rules in place for all the log entries it will generate, but I want to be able to test to for the lack of a 'finished' log entry between say midnight to 11:59pm. Is this possible? Or is there a work around to make it possible?


--
Ita erat quando hic adveni.

Mark Haney
Sr. Systems Administrator
ERC Broadband
(828) 350-2415


OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.