Prelude-LML is a signature-based log analyzer monitoring your log file and received syslog messages for suspicious activity.
It handle events generated by a large set of components, including but not limited to: APC Emu, BigIP, Cisco PIX, Clamav, Dell-OM, Grsecurity, Honeyd, ipchains, Netfilter, ipfw, Nokia ipso, Apache ModSecurity, Ms-SQL, Nagios, Norton Antivirus Corporate Edition, NTsyslog, Pam, Portsentry, Postfix, Proftpd, SSH, and others.
· The ability to use regular expressions in plugins.rules to define monitored sources was added.
· This can be very useful when combined to file globbing.
· When the "·" keyword is used, the data is passed to the upper layer without trying to match anything.
· A problem with handling of empty context was fixed.
· The log parser was made more robust.
· Описание и дополнения от редакторов и пользователей сайта