[Prelude Hybrid IDS] #307: Additional prefix-regex to deal with apache error_log file format
"Prelude Hybrid IDS" <[email protected]> Wed, 20 Aug 2008 08:24:47 -0000
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#307: Additional prefix-regex to deal with apache error_log file format
--------------------------------+-------------------------------------------
Reporter: Shurcik | Type: enhancement
Status: new | Priority: normal
Milestone: Prelude-LML 0.9.13 | Component: prelude-lml
Version: 0.9 | Severity: normal
Keywords: apache |
--------------------------------+-------------------------------------------
Current prelude-lml configuration has httpd.rules that deal with errors in
apache logs but [format=apache] section in prelude-lml.conf deals with
only common log format, not error log format. So nobody is able to parse
errors since prelude-lml.conf doesn't match them. Here're the additions to
prelude-lml.conf (I added additional blank lines, so remove them):
[format=apache-error]
time-format = "%a %b %d %H:%M:%S %Y"
prefix-regex = "^\[(?P<timestamp>.{24})\] \S+ \[client (?P<hostname>\S+)\]
"
file = /var/log/httpd/error_log
--
Ticket URL: <https://trac.prelude-ids.org/ticket/307>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel