--- /dev/null
+<!-- @(#) $Id: ./etc/rules/spamd_rules.xml, 2011/09/08 dcid Exp $
+
+ - Spamd rules for OSSEC.
+ - Author: Peter Ahlert <peter@ifup.de>
+ - Author: Daniel B. Cid
+ - License: http://www.ossec.net/en/licensing.html
+ -->
+
+<!-- STILL BETA -->
+
+<group name="syslog,spamd,">
+ <rule id="3500" level="0" noalert="1">
+ <match>^spamd</match>
+ <description>Grouping for the spamd rules</description>
+ </rule>
+
+ <rule id="3501" level="0">
+ <if_sid>3500</if_sid>
+ <match>: result:</match>
+ <description>SPAMD result message (not very usefull here).</description>
+ </rule>
+
+ <rule id="3502" level="0">
+ <if_sid>3500</if_sid>
+ <match> checking message | processing message </match>
+ <description>Spamd debug event (reading message).</description>
+ </rule>
+</group> <!-- SYSLOG,SPAMD -->
+
+
+<!-- EOF -->