Messages by Thread
-
-
[Simple-evcorr-users] Correlation Upon Aggregation
Santhosh Kumar
-
[Simple-evcorr-users] Question on rule
James Lay
-
[Simple-evcorr-users] an update to sec FAQ
Risto Vaarandi
-
[Simple-evcorr-users] list of suppress events
Kagan, Eli
-
[Simple-evcorr-users] SingleWithThreshold reference current input line
Dusan Sovic
-
[Simple-evcorr-users] Suppress rule and continue filed support
Dusan Sovic
-
[Simple-evcorr-users] sec-2.8.1 released
Risto Vaarandi
-
[Simple-evcorr-users] updates to SEC FAQ
Risto Vaarandi
-
[Simple-evcorr-users] sec-2.8.0 released
Risto Vaarandi
-
[Simple-evcorr-users] Whitelisting or Blacklisting
S, Santosh
-
[Simple-evcorr-users] Accesing nested fields in json logs
Alberto Corton
-
[Simple-evcorr-users] sec-2.8.alpha2 released
Risto Vaarandi
-
[Simple-evcorr-users] Ubuntu service file
James Lay
-
[Simple-evcorr-users] Way to corelate 2 rules with treshold
Przemysław Orzechowski
-
[Simple-evcorr-users] sec-2.8.alpha1 released
Risto Vaarandi
-
[Simple-evcorr-users] keepalive
Kagan, Eli
-
[Simple-evcorr-users] Storing events of a SingleWithThreshold rule
Alberto Corton
-
[Simple-evcorr-users] rule reuse and file splitting
Kagan, Eli
-
[Simple-evcorr-users] Input log missing in syslog-ng
Inderjeet Singh
-
[Simple-evcorr-users] design question about dynamic inputs
Risto Vaarandi
-
[Simple-evcorr-users] PairWithWindow rule and timestamp of the first event
Riska, Roni (Nokia - FI/Espoo)
-
[Simple-evcorr-users] SEC use cases -> modifying the state of the world
Andrew Nieuwsma
-
[Simple-evcorr-users] SEC Reading problem
Jaren Peich
-
[Simple-evcorr-users] Variable set from one rule, to use with action on another rule.
Kamil B
-
[Simple-evcorr-users] Ignore first n 'bar' if 'foo' occurs
Kamil B
-
[Simple-evcorr-users] sec-2.7.12 released
Risto Vaarandi
-
[Simple-evcorr-users] Get last event in SingleWithThreshold rule
Riska, Roni (Nokia - FI/Espoo)
-
[Simple-evcorr-users] reading utf16 log files
Risto Vaarandi
-
[Simple-evcorr-users] Log Rotation
Joanna Christou
-
[Simple-evcorr-users] Understanding % when creating config file global variables
Stuart Kendrick
-
[Simple-evcorr-users] look-up a string in a hash, then write hash value
Stuart Kendrick
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Risto Vaarandi
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Jaren Peich
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Stuart Kendrick
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Risto Vaarandi
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Risto Vaarandi
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Stuart Kendrick
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Risto Vaarandi
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Stuart Kendrick
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Risto Vaarandi
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Risto Vaarandi
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Stuart Kendrick
-
Re: [Simple-evcorr-users] look-up a string in a hash, then write hash value
Stuart Kendrick
-
[Simple-evcorr-users] SEC_SHUTDOWN event/delay
Peter Eckel
-
[Simple-evcorr-users] potential issues with mailing list
Risto Vaarandi
-
[Simple-evcorr-users] Sec Rule problem
Jaren Peich
-
[Simple-evcorr-users] integration with systemd (update to SEC FAQ)
Risto Vaarandi
-
[Simple-evcorr-users] Regexp matching against context names
Dusan Sovic
-
[Simple-evcorr-users] Sec error (invalid regular expression)
James Lay
-
[Simple-evcorr-users] How to mail with a multiline body?
Tom Damon
-
[Simple-evcorr-users] Window being ignored
Yahoo
-
[Simple-evcorr-users] Negation
James Lay
-
[Simple-evcorr-users] VIM syntax file?
James Lay
-
[Simple-evcorr-users] sec-2.7.11 released
Risto Vaarandi
-
[Simple-evcorr-users] some changes in the next sec release (feedback appreciated)
Risto Vaarandi
-
[Simple-evcorr-users] Test IF correlation operation exist then take action
Dusan Sovic
-
[Simple-evcorr-users] Content of pattern match cache after synthetic event injection
Dusan Sovic
-
[Simple-evcorr-users] a very dumb issue
Martin Etcheverry
-
[Simple-evcorr-users] problem sending events from rsyslog to sec
Martin Etcheverry
-
[Simple-evcorr-users] trying to create a rule to alarm when the i get one alarm and the cancelation didn´t arrive in 10 minutes
Martin Etcheverry
-
[Simple-evcorr-users] Variable access lcall
Jaren Peich
-
[Simple-evcorr-users] From start specific file
Jaren Peich
-
[Simple-evcorr-users] unique login failures
Varun
-
[Simple-evcorr-users] about to use sec to vcenter events
Martin Etcheverry
-
[Simple-evcorr-users] Auditd EXECVE message correlation
Nikolay Srebniuk
-
[Simple-evcorr-users] Auditd EXECVE message correlation
Nikolay Srebniuk