[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[ossec-list] Re: Seeking help with custom rule
Greetings Daniel:
That works; thank you. A related question.
What if the log was as follows from Apache error_log:
[Tue Sep 18 20:53:47 2007] [error] [client 203.122.241.211] File does
not exist: /hsphere/local/home/april3/mythicalrealm.com/_vti_bin/
shtml.exe/_vti_rpc
And I wanted to key in on
"File does not exist" and "shtml.exe" and "_vti_rpc"
What would the match look like then?
Thank you.
OSSEC home |
Main Index |
Thread Index
OSSEC project: www.ossec.net.
Mailling list information: http://www.ossec.net/en/mailing_lists.html.