X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=etc%2Frules%2Flog-entries%2F2501;fp=etc%2Frules%2Flog-entries%2F2501;h=397dfd57bb23a80c6674715d0d15e6a0f78c3077;hp=0000000000000000000000000000000000000000;hb=ff0e686ac67bbd82b60c277eb324910dbc60f65f;hpb=33a81e69474ae91ecec4e991debe59e26bb330fd diff --git a/etc/rules/log-entries/2501 b/etc/rules/log-entries/2501 new file mode 100755 index 0000000..397dfd5 --- /dev/null +++ b/etc/rules/log-entries/2501 @@ -0,0 +1,28 @@ +Nov 9 05:00:07 ensim +proftpd[21141]: ensim.domain.com +(p50832E46.dip.t-dialin.net[80.131 +.46.70]) - FTP session opened. +Nov 9 05:00:09 ensim +proftpd[21141]: ensim.domain.com +(p50832E46.dip.t-dialin.net[80.131 +.46.70]) - no such user +'anonymous' +Nov 9 05:00:14 ensim +proftpd[21141]: ensim.domain.com +(p50832E46.dip.t-dialin.net[80.131 +.46.70]) - FTP session closed. +Nov 9 06:12:41 ensim +proftpd[24994]: ensim.domain.com +(ool-18bba13b.dyn.optonline.net[24 +.187.161.59]) - FTP session +opened. +Nov 9 06:12:41 ensim +proftpd[24994]: ensim.domain.com +(ool-18bba13b.dyn.optonline.net[24 +.187.161.59]) - no such user +'vgodz' +Nov 9 06:12:41 ensim +proftpd[24994]: ensim.domain.com +(ool-18bba13b.dyn.optonline.net[24 +.187.161.59]) - FTP session +closed.