Has anyone written a regex for parsing the OSSEC alerts syslog format? It often is a combination event holding 10 or more events, so the line breaks make it think the syslog entry has ended when it has not.
↧
Has anyone written a regex for parsing the OSSEC alerts syslog format? It often is a combination event holding 10 or more events, so the line breaks make it think the syslog entry has ended when it has not.