Rule matching in preludedb-admin
Colin <[email protected]> Wed, 26 Jan 2011 14:23:24 +0000
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
Fellow users of prelude, I was trying to understand the rule matching in preludedb-admin so I can make some scripts to extract statistical information. I want to know if I can use preludedb-admin, more specific the criteria, as regular expressions, for example: preludedb-admin count alert "type etc.." --criteria "alert.create_time >= date && (alert.source.etc <> '10.10.10.*' || alert.target.etc <> '10.10.10.*' && something else)" I am having some trouble getting values for related dates and networks (source and targets). I suspect that the software may not have support for this kind of expressions, such as negations for example. I would like to know if preludedb-admin would execute this: check all events and do rule matching OR work as an expression. Thanks. -- Colin _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-technologies.com/mailman/listinfo/prelude-user