C.4. Logging thresholds

Section heading (see Section 4.3> for more details):

[Log]

Entries:

MailSeverity=list of [optional specifier]threshold

PrintSeverity=list of [optional specifier]threshold

LogSeverity=list of [optional specifier]threshold

SyslogSeverity=list of [optional specifier]threshold

PreludeSeverity=list of [optional specifier]threshold

ExportSeverity=list of [optional specifier]threshold

ExternalSS="REPLACEABLE" >list of [optional specifier]threshold

ExternalSS="REPL > 

Each section may occur multiple times.

NoteNote
 

You can explicitely end the configuration file with an [EOF] (on a separate line), but this is not required, unless there is some junk beyond that may confuse the parser. A PGP signature does not qualify as 'junk' if samhain is compiled to verify the signature.

C.1.1. Conditionals

Conditional inclusion of entries for some host(s) is supported via any number of @hostname/@end directives. @hostname and @end must each be on separate lines. Lines in between will only be read if hostname (which may be a regular expression) matches the local host.

Likewise, conditional inclusion of entries based on system type is supported via any number of $sysname:release:machine/$end directives. sysname:release:machine for the