Focus on IDS
OSSEC and Windows messages Apr 20 2010 01:34PM
evilwon12 yahoo com
I am trying to match on a windows error message and am not having any luck. What I do not want to do is ignore the rule completely, only certain messages.

An example message is this:

Integrity checksum changed for:


I want to filter out based on "directory3" OR a sub-string on that. I have not been able to filter on anything in the message string. My thoughts are that the forward and back slashes are causing the problem.

Has anyone else ran into this or know of a solution to this?


