Rule matching in preludedb-admin

Colin <[email protected]> Wed, 26 Jan 2011 14:23:24 +0000
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
Fellow users of prelude,
I was trying to understand the rule matching in preludedb-admin so I
can make some scripts to extract statistical information.
I want to know if I can use preludedb-admin, more specific the
criteria, as regular expressions, for example:
preludedb-admin count alert "type etc.." --criteria "alert.create_time
>= date && (alert.source.etc <> '10.10.10.*' || alert.target.etc <>
'10.10.10.*' && something else)"

I am having some trouble getting values for related dates and networks
(source and targets). I suspect that the software may not have support
for this kind of expressions, such as negations for example.
I would like to know if preludedb-admin would execute this: check all
events and do rule matching OR work as an expression.

Thanks.
-- 
Colin
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-technologies.com/mailman/listinfo/prelude-user