Re: Prelude-lml sensor

Yoann Vandoorselaere <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <1247233712.31201.30.camel@arwen>
Hi Matteo,

Le mercredi 25 mars 2009 à 12:45 +0100, Matteo Michelini a écrit :
> I'm trying to configure prelude-lml sensor but I'm wondering what's the
> meaning of prefix-regex into the prelude-lml.conf file.
> 
> I thought that prefix-regex was used to match the first part of the log
> trail and then the trails not-filtered by this regex were redirected to
> the specific *.rules under ruleset/.
> 
> But prefix-regex doesn't filter anything.... So I cannot imagine what's
> its purpose.

You are correct: prefix-regex won't filter out unmatched lines, this is
a security feature so that unmatched events will still go through
Prelude-LML signature and get analyzed.

The point of prefix regex is to retrieve some common information from
the log's header, like the hostname, the process PID or name.

Reading the example you provided, it's not clear exactly what you were
trying to achieve. Could you provide us more details about that?

[...]

Regards,

-- 
Yoann Vandoorselaere <[email protected]>

_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.