i can't match the port at the end of this message.
msg:
Feb 06 15:56:09 higgs sshd[902]: Server listening on 0.0.0.0 port 22.
rule:
%msgtime% %apphost% %appname% [ %sessionid% ] : Server listening on %srcipv4% port %integer% .
It's a minor issue in this simple case but it's a bit confusing while writing rules.
Yes, that's definitely a problem. Have to figure out a good way to recognize that without doing too much forward looking (otherwise performance will get hammered.) Let me keep this open for now and think about it.
Hi,
i can't match the port at the end of this message.
It's a minor issue in this simple case but it's a bit confusing while writing rules.