OSSEC的decoder语法

选项:

decoder

Attributes:

  • id::
  • name:
  • type:
  • status:
decoder.parent
decoder.program_name

Allowed: Any OS_Match/sregex Syntax

decoder.prematch

Allowed: Any OS_Match/sregex Syntax

decoder.regex

Allowed: Any OR_Regex/regex Syntax

decoder.order
decoder.fts
decoder.ftscomment

Unused at this time.

你可能感兴趣的:(OS)