e17793cbe5
Changelog prelude-lml: - Ability to use regular expressions in plugins.rules to define monitored sources, this can be very useful when combined to file globing. - [SPEEDUP] When the "*" keyword is used, the data is passed to the upper layer without trying to match anything. - Fix NULL pointer dereference when a rule reference an existing, but empty context (fix #226). - Remove deprecated use of prelude_client_print_setup_error(), directly handled via prelude_perror(). - Make the log parser more robust. PR: 112835 Submitted by: Robin Gruyters <r.gruyters@yirdis.nl> (maintainer)
74 lines
3.1 KiB
Text
74 lines
3.1 KiB
Text
@comment $FreeBSD$
|
|
bin/prelude-lml
|
|
@unexec if cmp -s %D/etc/prelude-lml/plugins.rules %D/etc/prelude-lml/plugins.rules-dist; then rm -f %D/etc/prelude-lml/plugins.rules; fi
|
|
etc/prelude-lml/plugins.rules-dist
|
|
@exec if [ ! -f %D/etc/prelude-lml/plugins.rules ] ; then cp -p %D/%F %B/plugins.rules; fi
|
|
@unexec if cmp -s %D/etc/prelude-lml/prelude-lml.conf %D/etc/prelude-lml/prelude-lml.conf-dist; then rm -f %D/etc/prelude-lml/prelude-lml.conf; fi
|
|
etc/prelude-lml/prelude-lml.conf-dist
|
|
@exec if [ ! -f %D/etc/prelude-lml/prelude-lml.conf ] ; then cp -p %D/%F %B/prelude-lml.conf; fi
|
|
etc/prelude-lml/ruleset/apc-emu.rules
|
|
etc/prelude-lml/ruleset/arbor.rules
|
|
etc/prelude-lml/ruleset/arpwatch.rules
|
|
etc/prelude-lml/ruleset/bonding.rules
|
|
etc/prelude-lml/ruleset/cacti-thold.rules
|
|
etc/prelude-lml/ruleset/checkpoint.rules
|
|
etc/prelude-lml/ruleset/cisco-asa.rules
|
|
etc/prelude-lml/ruleset/cisco-common.rules
|
|
etc/prelude-lml/ruleset/cisco-css.rules
|
|
etc/prelude-lml/ruleset/cisco-ips.rules
|
|
etc/prelude-lml/ruleset/cisco-router.rules
|
|
etc/prelude-lml/ruleset/cisco-vpn.rules
|
|
etc/prelude-lml/ruleset/clamav.rules
|
|
etc/prelude-lml/ruleset/dell-om.rules
|
|
etc/prelude-lml/ruleset/exim.rules
|
|
etc/prelude-lml/ruleset/f5-bigip.rules
|
|
etc/prelude-lml/ruleset/grsecurity.rules
|
|
etc/prelude-lml/ruleset/honeyd.rules
|
|
etc/prelude-lml/ruleset/httpd.rules
|
|
etc/prelude-lml/ruleset/ipchains.rules
|
|
etc/prelude-lml/ruleset/ipfw.rules
|
|
etc/prelude-lml/ruleset/ipso.rules
|
|
etc/prelude-lml/ruleset/linksys-wap11.rules
|
|
etc/prelude-lml/ruleset/modsecurity.rules
|
|
etc/prelude-lml/ruleset/ms-cluster.rules
|
|
etc/prelude-lml/ruleset/ms-sql.rules
|
|
etc/prelude-lml/ruleset/nagios.rules
|
|
etc/prelude-lml/ruleset/navce.rules
|
|
etc/prelude-lml/ruleset/netapp-ontap.rules
|
|
etc/prelude-lml/ruleset/netfilter.rules
|
|
etc/prelude-lml/ruleset/netscreen.rules
|
|
etc/prelude-lml/ruleset/ntsyslog.rules
|
|
etc/prelude-lml/ruleset/openhostapd.rules
|
|
etc/prelude-lml/ruleset/pam.rules
|
|
etc/prelude-lml/ruleset/pcanywhere.rules
|
|
etc/prelude-lml/ruleset/pcre.rules
|
|
etc/prelude-lml/ruleset/portsentry.rules
|
|
etc/prelude-lml/ruleset/postfix.rules
|
|
etc/prelude-lml/ruleset/proftpd.rules
|
|
etc/prelude-lml/ruleset/qpopper.rules
|
|
etc/prelude-lml/ruleset/selinux.rules
|
|
etc/prelude-lml/ruleset/sendmail.rules
|
|
etc/prelude-lml/ruleset/shadow-utils.rules
|
|
etc/prelude-lml/ruleset/single.rules
|
|
etc/prelude-lml/ruleset/sonicwall.rules
|
|
etc/prelude-lml/ruleset/spamassassin.rules
|
|
etc/prelude-lml/ruleset/squid.rules
|
|
etc/prelude-lml/ruleset/ssh.rules
|
|
etc/prelude-lml/ruleset/sudo.rules
|
|
etc/prelude-lml/ruleset/tripwire.rules
|
|
etc/prelude-lml/ruleset/vigor.rules
|
|
etc/prelude-lml/ruleset/vpopmail.rules
|
|
etc/prelude-lml/ruleset/webmin.rules
|
|
etc/prelude-lml/ruleset/wu-ftp.rules
|
|
etc/prelude-lml/ruleset/zywall.rules
|
|
etc/prelude-lml/ruleset/zyxel.rules
|
|
include/prelude-lml/prelude-lml.h
|
|
lib/prelude-lml/debug.la
|
|
lib/prelude-lml/debug.so
|
|
lib/prelude-lml/pcre.la
|
|
lib/prelude-lml/pcre.so
|
|
@dirrm include/prelude-lml
|
|
@dirrm lib/prelude-lml
|
|
@dirrm etc/prelude-lml/ruleset
|
|
@dirrmtry etc/prelude-lml
|
|
@unexec echo "If you are permanently removing this port, you should remove ${PKG_PREFIX}/etc/prelude-lml and /var/spool/prelude-lml directories to clean up any configuration and logfile metadata files left." | fmt
|