annotate syslog2iptables.conf @ 14:2a7161b03b94

final documentation, rpm builds properly
author carl
date Sat, 17 Dec 2005 17:06:28 -0800
parents d76f9ff42487
children 0d65c3de34fd
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
9
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
1 threshold 550;
3
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
2
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
3 ignore {
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
4 127.0.0.0/8; // localhost
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
5 205.147.40.32/26; // 510sg
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
6 205.147.0.100/24; // digilink
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
7 205.147.39.128/25; // ams
1
551433a01cab initial coding
carl
parents:
diff changeset
8 };
551433a01cab initial coding
carl
parents:
diff changeset
9
5
276c4edc8521 initial coding
carl
parents: 4
diff changeset
10 file "/var/log/cisco.log" {
3
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
11 pattern "Internet_Firewall denied (tcp|udp) ([^(]*)" {
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
12 index 2; // zero based
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
13 bucket 200;
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
14 };
1
551433a01cab initial coding
carl
parents:
diff changeset
15 };
3
8fe310e5cd44 initial coding
carl
parents: 1
diff changeset
16
5
276c4edc8521 initial coding
carl
parents: 4
diff changeset
17 file "/var/log/secure" {
276c4edc8521 initial coding
carl
parents: 4
diff changeset
18 pattern "sshd.*Failed password .* from ::ffff:(.*) port" {
276c4edc8521 initial coding
carl
parents: 4
diff changeset
19 index 1; // zero based
9
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
20 bucket 400;
5
276c4edc8521 initial coding
carl
parents: 4
diff changeset
21 };
276c4edc8521 initial coding
carl
parents: 4
diff changeset
22 pattern "sshd.*Failed password .* from (.*) port" {
276c4edc8521 initial coding
carl
parents: 4
diff changeset
23 index 1; // zero based
9
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
24 bucket 400;
5
276c4edc8521 initial coding
carl
parents: 4
diff changeset
25 };
276c4edc8521 initial coding
carl
parents: 4
diff changeset
26 };
276c4edc8521 initial coding
carl
parents: 4
diff changeset
27
9
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
28 // file "/var/log/messages" {
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
29 // pattern "sshd.pam_unix.*authentication failure.*rhost=(.*) user=" {
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
30 // index 1; // zero based
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
31 // bucket 300;
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
32 // };
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
33 // pattern "sshd.pam_unix.*authentication failure.*rhost=(.*)$" {
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
34 // index 1; // zero based
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
35 // bucket 300;
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
36 // };
d76f9ff42487 initial coding
carl
parents: 5
diff changeset
37 // };