########################################################################## # $Id$ ########################################################################## # $Log: eventlog.conf,v $ # Revision 1.2 2007/10/01 16:55:18 mike # Removed OnlyHost config in these files. It was not working correctly and has been added in the main script when it is needed. -mgt # # Revision 1.1 2007/04/28 22:50:24 bjorn # Added files for Windows Event Log, by Orion Poplawski. These are for # Windows events logged to a server, using Snare Agent or similar. # ########################################################################## # What actual file? Defaults to LogPath if not absolute path.... LogFile = eventlog # If the archives are searched, here is one or more line # (optionally containing wildcards) that tell where they are... # Note: if these are gzipped, you need to end with a .gz even if # you use wildcards... #If you use a "-" in naming add that as well -mgt Archive = eventlog.* Archive = eventlog.*.gz Archive = archiv/eventlog.* Archive = archiv/eventlog.*.gz Archive = eventlog-* Archive = eventlog-*.gz Archive = archiv/eventlog-* Archive = archiv/eventlog-*.gz # Expand the repeats (actually just removes them now) *ExpandRepeats # Now, lets remove the services we don't care about at all... #*RemoveService = talkd # Keep only the lines in the proper date range... *ApplyStdDate # vi: shiftwidth=3 tabstop=3 et