Merge tag 'upstream/2.7'
[ossec-hids.git] / contrib / logtesting / 39 / res
diff --git a/contrib/logtesting/39/res b/contrib/logtesting/39/res
new file mode 100644 (file)
index 0000000..f3d7668
--- /dev/null
@@ -0,0 +1,16 @@
+**Phase 1: Completed pre-decoding.
+       full event: 'Jan 12 20:48:29 elrond sshd[19734]: refused connect from accsys.elink.net.au (203.31.101.11)'
+       hostname: 'elrond'
+       program_name: 'sshd'
+       log: 'refused connect from accsys.elink.net.au (203.31.101.11)'
+
+**Phase 2: Completed decoding.
+       decoder: 'sshd'
+
+**Phase 3: Completed filtering (rules).
+       Rule id: '2503'
+       Level: '5'
+       Description: 'Connection blocked by Tcp Wrappers.'
+**Alert to be generated.
+
+