1 **Phase 1: Completed pre-decoding.
2 full event: 'May 26 19:40:25 enigma sudo: dcid : 3 incorrect password attempts ; TTY=ttyp0 ; PWD=/var/www/htdocs ; USER=root ; COMMAND=/bin/ls'
5 log: 'dcid : 3 incorrect password attempts ; TTY=ttyp0 ; PWD=/var/www/htdocs ; USER=root ; COMMAND=/bin/ls'
7 **Phase 2: Completed decoding.
10 **Phase 3: Completed filtering (rules).
13 Description: 'Three failed attempts to run sudo'
14 **Alert to be generated.