X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fids_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fids_rules.xml;h=0000000000000000000000000000000000000000;hp=7fe49937718219dfefffd06b94b0fdb03f2054cd;hb=946517cefb8751a43a89bda4220221f065f4e5d1;hpb=3f728675941dc69d4e544d3a880a56240a6e394a diff --git a/debian/ossec-hids/var/ossec/rules/ids_rules.xml b/debian/ossec-hids/var/ossec/rules/ids_rules.xml deleted file mode 100644 index 7fe4993..0000000 --- a/debian/ossec-hids/var/ossec/rules/ids_rules.xml +++ /dev/null @@ -1,104 +0,0 @@ - - - -8 - - - - ids - - First time this IDS alert is generated. - fts, - - - - ids - srcip, id - IDS event. - - - - - 20100, 20101 - snort - - ^1:1852:|^1:368:|^1:384:|^1:366:|^1:402:|^1:408:|^1:1365:| - ^1:480:|^1:399:|^1:2925: - Ignored snort ids. - - - - - 20100, 20101 - dragon-nids - - ^EOL$|^SOF$|^HEARTBEAT$|^DYNAMIC-TCP$|^DYNAMIC-UDP$ - Ignored snort ids. - - - - 20101 - - id - Multiple IDS alerts for same id. - - - - 20101 - - srcip, id - Multiple IDS events from same source ip. - - - - - - 20151 - - - srcip, id - Multiple IDS events from same source ip - (ignoring now this srcip and id). - - - - 20152 - - id - Multiple IDS alerts for same id - (ignoring now this id). - -