X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=etc%2Frules%2Fbro-ids_rules.xml;fp=etc%2Frules%2Fbro-ids_rules.xml;h=b42657f4b43f1b7ce2128bfac6e9c6a8989aecdb;hp=0000000000000000000000000000000000000000;hb=6ef2f786c6c8ead94841b5f93baf9f43421f08c8;hpb=301048b51990573e58a30dc4a5bb4ec285cad554 diff --git a/etc/rules/bro-ids_rules.xml b/etc/rules/bro-ids_rules.xml new file mode 100755 index 0000000..b42657f --- /dev/null +++ b/etc/rules/bro-ids_rules.xml @@ -0,0 +1,75 @@ + + + + + + bro-ids + Grouping for all bro-ids events. + + + + 52000 + Starting incremental serialization + Bro-ids has been started. + + + + 52000 + Finished incremental serialization + Bro-ids has been stopped. + + + + 52000 + msg=AckAboveHole + XXX Ack Above Hole + + + + 52000 + msg=ContentGap + XXX Content Gap + + + + 52000 + no=ResourceSummary + Bro-ids resource summary. + + + + 52000 + no=PortScanSummary + Bro-ids port scan summary. + + + + 52000 + no=ZoneTransfer + Bro-ids Zone Transfer alert. + + + + 52000 + no=SensitivePortMapperAccess + Bro-ids detected acces to the portmapper port. + + + + 52000 + no=PortScan + Bro-ids detected a portscan. + + + + + + +