Quantcast
Viewing all articles
Browse latest Browse all 783

Syslog parsing for OSSEC syslog alerts

Has anyone written a regex for parsing the OSSEC alerts syslog format? It often is a combination event holding 10 or more events, so the line breaks make it think the syslog entry has ended when it has not.


Viewing all articles
Browse latest Browse all 783

Trending Articles