Thanks Again Henning!!!<br>
I truly appreciate it!<br><br><div><span class="gmail_quote">On 12/15/05, <b class="gmail_sendername">Henning Markussen</b> <<a href="mailto:hm@mib.dk">hm@mib.dk</a>> wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
Antonio Brown wrote:<br>> Hello All,<br>><br>> I was wondering which of the two formats below would you use when<br>> filtering using syslog-ng:<br>><br>> filter f_pix { match(PIX) and not<br>> match("
1.2.3.4|1.2.3.4|1.2.3.4|1.2.3.4|netmask("*MailScanner warning:<br>> numerical links are often malicious:*<br>> <a href="http://1.2.3.4/28")|netmask("1.2.3.4/20")|netmask("1.2.3.4/22")|netmask("1.2.3.4/28")">
1.2.3.4/28")|netmask("1.2.3.4/20")|netmask("1.2.3.4/22")|netmask("1.2.3.4/28")</a><br>> <<a href="http://1.2.3.4/28")|netmask("1.2.3.4/20")|netmask("1.2.3.4/22")|netmask("1.2.3.4/28")">
http://1.2.3.4/28")|netmask("1.2.3.4/20")|netmask("1.2.3.4/22")|netmask("1.2.3.4/28")</a>>")<br>> };<br>><br>> or......<br>><br>> filter f_pix { match(PIX)
<br>>
and not match(*MailScanner warning: numerical links are<br>> often malicious:* <a href="http://1.2.3.4">1.2.3.4</a> <<a href="http://1.2.3.4">http://1.2.3.4</a>>)<br>>
and not match(*MailScanner warning: numerical<br>> links are often malicious:* <a href="http://1.2.3.4">1.2.3.4</a> <<a href="http://1.2.3.4">http://1.2.3.4</a>>)<br>>
and not match(*MailScanner warning: numerical<br>> links are often malicious:* <a href="http://1.2.3.4">1.2.3.4</a> <<a href="http://1.2.3.4">http://1.2.3.4</a>>)<br>>
and not match(*MailScanner warning: numerical<br>> links are often malicious:* <a href="http://1.2.3.4">1.2.3.4</a> <<a href="http://1.2.3.4">http://1.2.3.4</a>>)<br>>
and not match(netmask("*MailScanner warning:<br>> numerical links are often malicious:* <a href="http://1.2.3.4/28"))">1.2.3.4/28"))</a> <<a href="http://1.2.3.4/28"))">http://1.2.3.4/28"))
</a>><br>>
and not match(netmask("*MailScanner warning:<br>> numerical links are often malicious:* <a href="http://1.2.3.4/20"))">1.2.3.4/20"))</a> <<a href="http://1.2.3.4/20"))">http://1.2.3.4/20"))
</a>><br>>
and not match(netmask("*MailScanner warning:<br>> numerical links are often malicious:* <a href="http://1.2.3.4/22"))">1.2.3.4/22"))</a> <<a href="http://1.2.3.4/22"))">http://1.2.3.4/22"))
</a>><br>>
and not match(netmask("*MailScanner warning:<br>> numerical links are often malicious:* <a href="http://1.2.3.4/28"))">1.2.3.4/28"))</a> <<a href="http://1.2.3.4/28"))">http://1.2.3.4/28"))
</a>><br>> };<br>><br>> I am currently using the latter, but it seems as if the individual ips<br>> and subnets would only be filtered if ALL is true. Would using "|", like<br>> in the first format, check for each individual ip or subnet and filter
<br>> accordingly? When I say filter I mean, I would like everything except<br>> for the individual IPs and subnets specified. I am not certain that this<br>> is appropriate format for filtering subnets, please advise....
<br>><br>> Thank You, in advance for your assistance!!!<br>><br>><br>> ------------------------------------------------------------------------<br>><br>> _______________________________________________
<br>> syslog-ng maillist - <a href="mailto:syslog-ng@lists.balabit.hu">syslog-ng@lists.balabit.hu</a><br>> <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng">https://lists.balabit.hu/mailman/listinfo/syslog-ng
</a><br>> Frequently asked questions at <a href="http://www.campin.net/syslog-ng/faq.html">http://www.campin.net/syslog-ng/faq.html</a><br>><br><br>the syntax for a <a href="http://10.0.0.0/24">10.0.0.0/24</a> netmask is
<br>netmask("<a href="http://10.0.0.0/255.255.255.0">10.0.0.0/255.255.255.0</a>")<br><br>- Henning<br><br>_______________________________________________<br>syslog-ng maillist - <a href="mailto:syslog-ng@lists.balabit.hu">
syslog-ng@lists.balabit.hu</a><br><a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>Frequently asked questions at <a href="http://www.campin.net/syslog-ng/faq.html">
http://www.campin.net/syslog-ng/faq.html</a><br><br></blockquote></div><br>