Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

integer with trailing dot recognized as float #3

Closed
cryptix opened this issue Feb 10, 2015 · 1 comment
Closed

integer with trailing dot recognized as float #3

cryptix opened this issue Feb 10, 2015 · 1 comment

Comments

@cryptix
Copy link

cryptix commented Feb 10, 2015

Hi,

i can't match the port at the end of this message.

msg:
Feb 06 15:56:09 higgs sshd[902]: Server listening on 0.0.0.0 port 22.

rule:
%msgtime% %apphost% %appname% [ %sessionid% ] : Server listening on %srcipv4% port %integer% .

It's a minor issue in this simple case but it's a bit confusing while writing rules.

@zhenjl
Copy link
Collaborator

zhenjl commented Feb 11, 2015

Yes, that's definitely a problem. Have to figure out a good way to recognize that without doing too much forward looking (otherwise performance will get hammered.) Let me keep this open for now and think about it.

@zhenjl zhenjl closed this as completed in 54cd230 Feb 28, 2015
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants