Displaying 1 result from an estimated 1 matches for "alert_incomplet".
Did you mean:
alert_incomplete
2006 Dec 19
0
Bug#403758: Logcheck rules for Snort
...y mistakes, or
things that could be simplified more. Rules are below:
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snort: .$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snort: (\`|\\+)-.*$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snort: alert_fragments:
(INACTIVE|ACTIVE)$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snort: alert_incomplete:
(INACTIVE|ACTIVE)$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snort: alert_large_fragments:
(INACTIVE|ACTIVE)$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snort: alert_multiple_requests:
(INACTIVE|ACTIVE)$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ snort: Detect Protocols:
[[:alpha:]].*$
^\w{3} [ :0-9]{11} [....