1 **Phase 1: Completed pre-decoding.
2 full event: 'May 4 11:17:42 niban su(pam_unix)[2298]: authentication failure; logname= uid=1342 euid=0 tty= ruser=dcid rhost= user=root'
5 log: 'May 4 11:17:42 niban su(pam_unix)[2298]: authentication failure; logname= uid=1342 euid=0 tty= ruser=dcid rhost= user=root'
7 **Phase 2: Completed decoding.
10 **Phase 3: Completed filtering (rules).
13 Description: 'User authentication failure.'
14 **Alert to be generated.