ZoneAlarm,host eq *,warning
ZoneAlarm,host eq *,display=type#date#time#ip#source#dest#transport
ZoneAlarm,type eq fwin,icon=desktopinbounddenied.bmp
Antivirus,ip eq *,display=date#time#ip#username#virusname#infectedfile
Antivirus,message ct infected,icon=virus.bmp
Antivirus,message ct infected,alert
Antivirus,message ct cleaned,icon=viruscleaned.bmp
Application Event,eventtype eq error,alert
System Event,eventtype eq error,alert
Security Event,eventtype eq error,alert
Application Event,eventtype eq error,display=label#eventtype#eventid#category#timegenerated#source#message
System Event,eventtype eq error,display=label#eventtype#eventid#category#timegenerated#source#message
Security Event,eventtype eq error,display=label#eventtype#eventid#description#category#timegenerated#source#message
Application Event,eventtype eq warning,warning
System Event,eventtype eq warning,warning
Security Event,eventtype eq warning,warning
Application Event,eventtype eq warning,display=label#eventtype#eventid#category#timegenerated#source#message
System Event,eventtype eq warning,display=label#eventtype#eventid#category#timegenerated#source#message
Security Event,eventtype eq warning,display=label#eventtype#eventid#description#category#timegenerated#source#message
Application Event,eventtype eq audit_failure,alert
System Event,eventtype eq audit_failure,alert
Security Event,eventtype eq audit_failure,alert
Application Event,eventtype eq audit_failure,display=label#eventtype#eventid#category#timegenerated#source#message
System Event,eventtype eq audit_failure,display=label#eventtype#eventid#category#timegenerated#source#message
Security Event,eventtype eq audit_failure,display=label#eventtype#eventid#description#category#timegenerated#source#message
Application Event,eventtype eq audit_success,drop
System Event,eventtype eq audit_success,drop
Security Event,eventtype eq audit_success,drop
Application Event,eventtype eq information,drop
System Event,eventtype eq information,drop
Security Event,eventtype eq information,drop
Running Services,ip eq *,display=display#servfilename#state#startup
Open shares,ip eq *,display=loghost#share#usergroup#rights#path
Startup config,ip eq *,display=loghost#line
ADS Scanner,ip eq * AND ads ct started,display=loghost#ads#size
ADS Scanner,ip eq * AND ads ct started,alert
Integrity checker,ip eq * AND line nc started,display=loghost#line
Integrity checker,ip eq * AND line nc started,alert
* Note that rules for Running Services, Open Shares, Startup config, ADS Scanner and Intergrity checker are not used in the Pro version, and having them would slow LogIDS 1.0 Pro a bit. I have displayed them here as an example for LogIDS 1.0 Open Source. Also note that rules concerning the Event viever are different from between the Open Source and Pro version (Pro is shown here). LogIDS 1.0 Pro does not need any Snort rules, so I have not put any here, but you shoulb know by now how to handle them. Also, you can apply rules for ComLog that can check for certains strings, like for example :