new upstream release (3.3.0); modify package compatibility for Stretch
[ossec-hids.git] / debian / ossec-hids / usr / share / doc / ossec-hids / contrib / logtesting / 31 / res
diff --git a/debian/ossec-hids/usr/share/doc/ossec-hids/contrib/logtesting/31/res b/debian/ossec-hids/usr/share/doc/ossec-hids/contrib/logtesting/31/res
new file mode 100644 (file)
index 0000000..9ad2d73
--- /dev/null
@@ -0,0 +1,20 @@
+**Phase 1: Completed pre-decoding.
+       full event: 'May 26 19:40:41 enigma sudo: dcid : TTY=ttyp0 ; PWD=/var/www/htdocs ; USER=root ; COMMAND=/usr/bin/tail /var/log/secure'
+       hostname: 'enigma'
+       program_name: 'sudo'
+       log: 'dcid : TTY=ttyp0 ; PWD=/var/www/htdocs ; USER=root ; COMMAND=/usr/bin/tail /var/log/secure'
+
+**Phase 2: Completed decoding.
+       decoder: 'sudo'
+       dstuser: 'dcid'
+       url: '/var/www/htdocs'
+       srcuser: 'root'
+       status: '/usr/bin/tail /var/log/secure'
+
+**Phase 3: Completed filtering (rules).
+       Rule id: '5403'
+       Level: '4'
+       Description: 'First time user executed sudo.'
+**Alert to be generated.
+
+