Skip to content

Commit

Permalink
Silence 100% of use in snap disks
Browse files Browse the repository at this point in the history
  • Loading branch information
Pablo Navarro authored and vikman90 committed Sep 4, 2018
1 parent f10198e commit 35cd825
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions rules/0015-ossec_rules.xml
Original file line number Diff line number Diff line change
Expand Up @@ -183,6 +183,13 @@
<description>List of the last logged in users.</description>
</rule>

<rule id="536" level="0">
<if_sid>531</if_sid>
<regex>'df -P':\s+/dev/loop\d+\s+\d+\s+\d+\s+0\s+100%\s+/snap/\w+/\d+</regex>
<description>Ignore snap disks because are always 100% of capacity</description>
</rule>


<rule id="550" level="7">
<category>ossec</category>
<decoded_as>syscheck_integrity_changed</decoded_as>
Expand Down

0 comments on commit 35cd825

Please sign in to comment.