Appendix C. filter.txt used in Chapter 10


services.log,Running Services,logip,loghost,loguser,logdate,logtime,display,name,state,account,servfilename,startup
shares.log,Open Shares,logip,loghost,loguser,logdate,logtime,share,usergroup,rights,path,remark
startup.log,Startup config,logip,loghost,loguser,logdate,logtime,line
adsscan.log,ADS Scanner,logip,loghost,loguser,logdate,logtime,ads,size
integrity.log,Integrity checker,logip,loghost,loguser,logdate,logtime,line
*.clg,ComLog,logip,loghost,loguser,logdate,logtime,line
appevent.log,Application Event,logip,loghost,loguser,logdate,logtime,line
sysevent.log,System Event,logip,loghost,loguser,logdate,logtime,line
secevent.log,Security Event,logip,loghost,loguser,logdate,logtime,line
ZAlog.txt,ZoneAlarm,ip,host,user,logdate,logtime,type,date,time,source,dest,transport
antivirus.log,Antivirus,ip,host,user,logdate,logtime,date,time,message,username,infectedfile,virusname
alert.ids,Snort,logip,loghost,loguser,logdate,logtime,line


Appendix B. Security Event ID description table
Appendix D. rules.txt used in Chapter 10