[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[ossec-list] Seeking help with custom rule



Greetings:

Apache error_log entry:

[Tue Sep 18 19:04:59 2007] [error] [client 195.244.128.240] Invalid
URI in request GET /../_vti_bin/shtml.exe/SI/contest.htm/map HTTP/1.1


How would I write the match portion of the rule to just key in on
"Invalid URI" and "shtml.exe"?

Thank you.



OSSEC home | Main Index | Thread Index


OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.