1 # Rule file for excluding known data in /var/log/messages 2 3 # Connection attempts: 4 ^.{15} (\w+) /kernel: Connection attempt to (TCP|UDP) \d+\.\d+\.\d+\.\d+:\d+ fro 5 m \d+\.\d+\.\d+\.\d+:\d+$ 6 7 # Syslog misc: 8 ^.{15} (\w+) last message repeated \d+ times$ 9 ^.{15} (\w+) newsyslog\[[0-9]+\]: logfile turned over$ 10 11 # ICMP Redirect 12 ^.{15} (\w+) /kernel: icmp redirect from [\d\.]+: [\d\.]+ => [\d\.]+$ 13 14 # FOO 15 ^.{15} (\w+) su: anders to root on /dev/tty 16 ^.{15} (\w+) /kernel: \w+: promiscuous mode 17 ^.{15} (\w+) /kernel: Limiting closed port RST response from