1 **Phase 1: Completed pre-decoding.
2 full event: 'May 4 11:18:52 niban su(pam_unix)[2307]: authentication failure; logname= uid=1342 euid=0 tty= ruser=dcid rhost= user=test'
5 log: 'May 4 11:18:52 niban su(pam_unix)[2307]: authentication failure; logname= uid=1342 euid=0 tty= ruser=dcid rhost= user=test'
7 **Phase 2: Completed decoding.
10 **Phase 3: Completed filtering (rules).
13 Description: 'User authentication failure.'
14 **Alert to be generated.