Merge tag 'upstream/2.7'
[ossec-hids.git] / contrib / logtesting / 2 / res
diff --git a/contrib/logtesting/2/res b/contrib/logtesting/2/res
new file mode 100644 (file)
index 0000000..ed00e95
--- /dev/null
@@ -0,0 +1,16 @@
+**Phase 1: Completed pre-decoding.
+       full event: 'Nov  1 14:54:03 melancia runuser: pam_unix(runuser:session): session opened for user root by (uid=0)'
+       hostname: 'melancia'
+       program_name: 'runuser'
+       log: 'pam_unix(runuser:session): session opened for user root by (uid=0)'
+
+**Phase 2: Completed decoding.
+       decoder: 'pam'
+
+**Phase 3: Completed filtering (rules).
+       Rule id: '5501'
+       Level: '3'
+       Description: 'Login session opened.'
+**Alert to be generated.
+
+