I have the following in regex.custom
Code: Select all
if (($lgfile eq $config{CUSTOM1_LOG}) and ($line =~ /^\[\S+\s+\S+\s+\S+\s+\S+\s+\S+\] \[error\] \[client (\S+)\] user (\S*) not found:/)) {
return ("Failed domain.org directory authentication from",$1,"DomainOrgUserNotFound","3","80,443","604800");
}
Code: Select all
1392112469|1.2.3.4|*|in|604800|lfd - (DomainOrgUserNotFound) Failed domain.org directory authentication from 1.2.3.4
Code: Select all
iptables v1.4.7: invalid port/service `alerts' specified
Try `iptables -h' or 'iptables --help' for more information.
If you disable LF_SELECT, then it works properly getting || on ports.
Be kind looking at this thoroughly please and fixing it as soon as possible!