+++ /dev/null
-**Phase 1: Completed pre-decoding.
- full event: 'May 26 20:16:17 lili sudo: dcid : TTY=pts/1 ; PWD=/home/dcid ; USER=root ; COMMAND=/usr/bin/vi /etc/sudoers'
- hostname: 'lili'
- program_name: 'sudo'
- log: 'dcid : TTY=pts/1 ; PWD=/home/dcid ; USER=root ; COMMAND=/usr/bin/vi /etc/sudoers'
-
-**Phase 2: Completed decoding.
- decoder: 'sudo'
- dstuser: 'dcid'
- url: '/home/dcid'
- srcuser: 'root'
- status: '/usr/bin/vi /etc/sudoers'
-
-**Phase 3: Completed filtering (rules).
- Rule id: '5403'
- Level: '4'
- Description: 'First time user executed sudo.'
-**Alert to be generated.
-
-