diff --git a/rules/0015-ossec_rules.xml b/rules/0015-ossec_rules.xml index a4e263771..b3f5b7d3c 100755 --- a/rules/0015-ossec_rules.xml +++ b/rules/0015-ossec_rules.xml @@ -183,6 +183,13 @@ List of the last logged in users. + + 531 + 'df -P':\s+/dev/loop\d+\s+\d+\s+\d+\s+0\s+100%\s+/snap/\w+/\d+ + Ignore snap disks because are always 100% of capacity + + + ossec syscheck_integrity_changed