Re: Prelude-lml sensor
Yoann Vandoorselaere <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <1247233712.31201.30.camel@arwen> |
Hi Matteo, Le mercredi 25 mars 2009 à 12:45 +0100, Matteo Michelini a écrit : > I'm trying to configure prelude-lml sensor but I'm wondering what's the > meaning of prefix-regex into the prelude-lml.conf file. > > I thought that prefix-regex was used to match the first part of the log > trail and then the trails not-filtered by this regex were redirected to > the specific *.rules under ruleset/. > > But prefix-regex doesn't filter anything.... So I cannot imagine what's > its purpose. You are correct: prefix-regex won't filter out unmatched lines, this is a security feature so that unmatched events will still go through Prelude-LML signature and get analyzed. The point of prefix regex is to retrieve some common information from the log's header, like the hostname, the process PID or name. Reading the example you provided, it's not clear exactly what you were trying to achieve. Could you provide us more details about that? [...] Regards, -- Yoann Vandoorselaere <[email protected]> _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user