1 **Phase 1: Completed pre-decoding.
2 full event: 'Sep 11 01:40:59 bogus.com su: ericx to root on /dev/ttyu0'
5 log: 'ericx to root on /dev/ttyu0'
7 **Phase 2: Completed decoding.
12 **Phase 3: Completed filtering (rules).
15 Description: 'User successfully changed UID to root.'
16 **Alert to be generated.