1 **Phase 1: Completed pre-decoding.
2 full event: 'Apr 27 15:22:23 niban sudo: dcid : TTY=pts/4 ; PWD=/home/dcid ; USER=root ; COMMAND=/usr/bin/tail /var/log/snort/alert.fast'
5 log: ' dcid : TTY=pts/4 ; PWD=/home/dcid ; USER=root ; COMMAND=/usr/bin/tail /var/log/snort/alert.fast'
7 **Phase 2: Completed decoding.
11 **Phase 3: Completed filtering (rules).
14 Description: 'First time user executed sudo.'
15 **Alert to be generated.