Re: [Prelude Hybrid IDS] #216: mod_security cleanup, and compatibility with version 2.0

"Prelude Hybrid IDS" <[email protected]> Tue, 12 Aug 2008 11:39:21 -0000
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#216: mod_security cleanup, and compatibility with version 2.0
-------------------------+--------------------------------------------------
 Reporter:  gegomez      |        Owner:  Peter Vrabec <[email protected]>
     Type:  defect       |       Status:  assigned                         
 Priority:  normal       |    Milestone:  Prelude-LML 0.9.13               
Component:  prelude-lml  |      Version:  0.9                              
 Severity:  normal       |   Resolution:                                   
 Keywords:               |  
-------------------------+--------------------------------------------------

Comment(by yoann):

 Overall, the generated alert look good! Here are some feedback &
 questions:

  * IDMEF require the Reference name and url to not be empty.
  * What is ModSec Rule ID?
  * What is UniqueID?
  * What exactly is the log format used in the ruleset log sample (doesn't
 look like raw log entry, there is no timestamp)?

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/216#comment:16>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel