Imported Upstream version 2.7
[ossec-hids.git] / contrib / logtesting / 11 / res
diff --git a/contrib/logtesting/11/res b/contrib/logtesting/11/res
new file mode 100644 (file)
index 0000000..a132a0f
--- /dev/null
@@ -0,0 +1,18 @@
+**Phase 1: Completed pre-decoding.
+       full event: 'Sep 11 01:40:59 bogus.com su: ericx to root on /dev/ttyu0'
+       hostname: 'bogus.com'
+       program_name: 'su'
+       log: 'ericx to root on /dev/ttyu0'
+
+**Phase 2: Completed decoding.
+       decoder: 'su'
+       srcuser: 'ericx'
+       dstuser: 'root'
+
+**Phase 3: Completed filtering (rules).
+       Rule id: '5303'
+       Level: '3'
+       Description: 'User successfully changed UID to root.'
+**Alert to be generated.
+
+