Re: [ossec-list] Re: WIn server 2008

2011-04-06 Thread Michael Starks
On Wed, 6 Apr 2011 10:00:11 -0700 (PDT), "joshua.gruber" wrote: This looks an oversight that is a potential problem on a lot of the rules in msauth_rules.xml. The event log ID's can be 5 digits (they go up to 65535) and so any id in the rule set that's less than 5 digits should have both the ^

Re: [ossec-list] Re: WIn server 2008

2011-04-06 Thread Michael Starks
On Wed, 6 Apr 2011 10:00:11 -0700 (PDT), "joshua.gruber" wrote: This looks an oversight that is a potential problem on a lot of the rules in msauth_rules.xml. The event log ID's can be 5 digits (they go up to 65535) and so any id in the rule set that's less than 5 digits should have both the ^

[ossec-list] Re: WIn server 2008

2011-04-06 Thread joshua.gruber
This looks an oversight that is a potential problem on a lot of the rules in msauth_rules.xml. The event log ID's can be 5 digits (they go up to 65535) and so any id in the rule set that's less than 5 digits should have both the ^ and the $, as you indicate. There might not be a 52901 yet but th