<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic questions on using IDS in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698907#M757141</link>
    <description>Hello,&lt;BR /&gt;&lt;BR /&gt;  I have IDS/9000 v2 on HPUX11.0 server. &lt;BR /&gt;  I recieve many alerts "Filesystem change detected" for activities made on files :&lt;BR /&gt;"/etc/syslog.conf.[0-9]+" (for example /etc/syslog.conf.6757).  I tried regular expression with *, &amp;lt;*&amp;gt; to exclude it but it doesn't work.&lt;BR /&gt;&lt;BR /&gt;  Is any way to exclude these files ?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Alex&lt;BR /&gt;</description>
    <pubDate>Mon, 08 Apr 2002 06:33:32 GMT</pubDate>
    <dc:creator>shacharg</dc:creator>
    <dc:date>2002-04-08T06:33:32Z</dc:date>
    <item>
      <title>questions on using IDS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698907#M757141</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;  I have IDS/9000 v2 on HPUX11.0 server. &lt;BR /&gt;  I recieve many alerts "Filesystem change detected" for activities made on files :&lt;BR /&gt;"/etc/syslog.conf.[0-9]+" (for example /etc/syslog.conf.6757).  I tried regular expression with *, &amp;lt;*&amp;gt; to exclude it but it doesn't work.&lt;BR /&gt;&lt;BR /&gt;  Is any way to exclude these files ?&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Alex&lt;BR /&gt;</description>
      <pubDate>Mon, 08 Apr 2002 06:33:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698907#M757141</guid>
      <dc:creator>shacharg</dc:creator>
      <dc:date>2002-04-08T06:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: questions on using IDS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698908#M757142</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Did you check the Administrator guide:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/J5083-90007/J5083-90007_top.html&amp;amp;con=/hpux/onlinedocs/J5083-90007/00/00/37-con.html&amp;amp;toc=/hpux/onlinedocs/J5083-90007/00/00/37-toc.html&amp;amp;searchterms=IDS&amp;amp;queryid=20020408-012039" target="_blank"&gt;http://www.docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/J5083-90007/J5083-90007_top.html&amp;amp;con=/hpux/onlinedocs/J5083-90007/00/00/37-con.html&amp;amp;toc=/hpux/onlinedocs/J5083-90007/00/00/37-toc.html&amp;amp;searchterms=IDS&amp;amp;queryid=20020408-012039&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;C.</description>
      <pubDate>Mon, 08 Apr 2002 07:15:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698908#M757142</guid>
      <dc:creator>Clemens van Everdingen</dc:creator>
      <dc:date>2002-04-08T07:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: questions on using IDS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698909#M757143</link>
      <description />
      <pubDate>Mon, 08 Apr 2002 07:39:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698909#M757143</guid>
      <dc:creator>Steve Steel</dc:creator>
      <dc:date>2002-04-08T07:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: questions on using IDS</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698910#M757144</link>
      <description>Use "/etc/syslog.conf." in the "Ignore these directories" in the Modifcation of files/directories template.&lt;BR /&gt;This string will match /etc/syslog.conf.1212 but also /etc/syslog.conf.otherstuff.&lt;BR /&gt;&lt;BR /&gt;If you refer to the regular expression section in the appendix of the admin guide, /etc/syslog.conf.&amp;lt;#&amp;gt;$ is what you really want, but unfortunately this does not work.&lt;BR /&gt;&lt;BR /&gt;BTW, you can only specify regular expressions for the "directory property;" the "file" properties are only used for exact string matches.  &lt;BR /&gt;&lt;BR /&gt;Pierre&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 22 Apr 2002 23:24:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/questions-on-using-ids/m-p/2698910#M757144</guid>
      <dc:creator>Pierre Pasturel</dc:creator>
      <dc:date>2002-04-22T23:24:31Z</dc:date>
    </item>
  </channel>
</rss>

