3 layers:
- default
- there are no include rules
- exclude rules are in one of
ignore.d.workstation,ignore.d.server, orignore.d.paranoid- exclude rule directory is based on "report level" in
logcheck.conf
- exclude rule directory is based on "report level" in
- subject line option in
logcheck.confisEVENTSUBJECT
- security/violations
- include rules are in
violations.d - exclude rules are in
violations.ignore.d - subject line option in
logcheck.confisSECURITYSUBJECT
- include rules are in
- attack/cracking
- include rules are in
cracking.d - exclude rules are in
cracking.ignore.d - subject line option in
logcheck.confisATTACKSUBJECT
- include rules are in