Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [ISSForum] User Defined Event |
|---|---|
| Date: | Fri, 21 Jan 2005 11:06:47 +0300 |
As I'd understood you ask about server sensor.
You should build a special segular expression, info about them is available
in sensor's docs (somewhere in apendixes, as I remmember).
All information that you want to be seen in event, can be returned only as
event parameters, so you can see it in details of event from SP Console.
For example, if you want to trigger events when line matches "TEMPLATE" and
to return entire string in details of event (in ':String' param, for
example), perss [Info...] button and in Name: field type ':String'
(without quotes), in Value: - type '{!}' without quotes too).
You can use regexp in Value: as well: if you need to return everything that
between words 'the' and 'pie' in ':adj' param, you have to assign:
Name: :adj
Value: the {!} pie
in case of 'the flaming pie' you'll get :adj == flaming
Hope this'll help
Good luck.
---
Best regards, Sergey V. Soldatov.
Information security department.
"Baxter, Kevin"
<Kevin.Baxter@indymacbank.c To: <issforum@iss.net>
om> cc:
Sent by: Subject: [ISSForum] User
Defined Event
issforum-bounces@iss.net
13.01.2005 22:02
I have setup a User Defined Event to monitor a .CSV file specific entry
and send an email. The problem I'm having is that I'm trying to return
the line that generated the event. I would appreciate any help.
Thanks
Kpb
_______________________________________________
ISSForum mailing list
ISSForum@iss.net
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum
To contact the ISSForum Moderator, send email to mod-issforum@iss.net
The ISSForum mailing list is hosted and managed by Internet Security
Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
_______________________________________________
ISSForum mailing list
ISSForum@iss.net
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
https://atla-mm1.iss.net/mailman/listinfo/issforum
To contact the ISSForum Moderator, send email to mod-issforum@iss.net
The ISSForum mailing list is hosted and managed by Internet Security Systems,
6303 Barfield Road, Atlanta, Georgia, USA 30328.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [ISSForum] Problem after changing sensor IP, Chan, Howard \(Hong Kong S.A.R.\) |
|---|---|
| Next by Date: | RE: [ISSForum] Admin Password, Sergey V Soldatov |
| Previous by Thread: | [ISSForum] User Defined Event, Baxter, Kevin |
| Next by Thread: | [ISSForum] Preventia mailfilter---- problems with it and Exchange 5.5, Muraca, Peppino |
| Indexes: | [Date] [Thread] [Top] [All Lists] |