Imported Upstream version 2.7
[ossec-hids.git] / contrib / logtesting / 27 / res
diff --git a/contrib/logtesting/27/res b/contrib/logtesting/27/res
new file mode 100644 (file)
index 0000000..5bf1a5f
--- /dev/null
@@ -0,0 +1,16 @@
+**Phase 1: Completed pre-decoding.
+       full event: 'May 26 19:40:25 enigma sudo: dcid : 3 incorrect password attempts ; TTY=ttyp0 ; PWD=/var/www/htdocs ; USER=root ; COMMAND=/bin/ls'
+       hostname: 'enigma'
+       program_name: 'sudo'
+       log: 'dcid : 3 incorrect password attempts ; TTY=ttyp0 ; PWD=/var/www/htdocs ; USER=root ; COMMAND=/bin/ls'
+
+**Phase 2: Completed decoding.
+       decoder: 'sudo'
+
+**Phase 3: Completed filtering (rules).
+       Rule id: '5401'
+       Level: '10'
+       Description: 'Three failed attempts to run sudo'
+**Alert to be generated.
+
+