Closed BernaldoPenasAntelo closed 4 years ago
This should probably be posted on the ossec-hids repository.
Not sure why it's not working, I've never actually used the program. I usually just use ossec-logtest
.
OK, thanks for your help, i open #1845 in ossec-hids repo
Following the docs, with the newest version of ossec running, i'm triying to create a custom rule with this expresion
I'm following the pcre2 syntax, but no matchings when i run my tests (i have used diferent online regexp engines and verify that the regexp it's correct and may verify my tests)
To test it i use the binary ossec-regex and get:
It give me no results, nothing happens.
I have tested that the binnary works
What i'm doing wrong, any help will be useful.
Thanks in advance.