I have some questions about writing rules for prelude-lml
"Paul Robert Marino" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
I already saked this on the user list and didnt get a responce Im hoping some one on the dev elopment list will know Ive noticed some things in the pcre-moc.c code which I haven't seen documented or seen examples of in existing rules. namely some of the properties you can apply to contexts specifically alert_on_destroy and alert_on_expire. my question is do I have to put a silent; in the rule to prevent it from double alerting? my other question is the expire is the number a time or a number of lines of log, and if it is a time what is the scale is it seconds or minutes. Also if any one knows where I can find full documentation of how to write rules please let me know, and if no such document exist then I would like to start writing a prelude-lml rules howto. _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel