########################################################################## # $Id$ ########################################################################## # $Log: evtapplication.conf,v $ # Revision 1.1 2007/04/28 22:50:24 bjorn # Added files for Windows Event Log, by Orion Poplawski. These are for # Windows events logged to a server, using Snare Agent or similar. # ########################################################################## # You can put comments anywhere you want to. They are effective for the # rest of the line. # this is in the format of = . Whitespace at the beginning # and end of the lines is removed. Whitespace before and after the = sign # is removed. Everything is case *insensitive*. # Yes = True = On = 1 # No = False = Off = 0 Title = "Application Event Log" # Which logfile group... LogFile = eventlog # Only give lines pertaining to the kernel service... *EventLogOnlyService = Application *RemoveHeaders # Ignore messages matching the given regex # $ignore_messages = Security policies were propagated with warning. 0x57 # Ignore messages about certain programs holding profile registry # entries open. This is a regular expression. # $ignore_profile_program = ^lsass\.exe$ # Ignore messages for these machines that can happen when they are off the # company netowrk (e.g. laptops). This is a regular expression. # $laptopsa = # vi: shiftwidth=3 tabstop=3 et