I was working on something like that and found that user wasn't picking up with my decoder. I ended up switching to using a match instead.
If you run the log entry through ossec-logtest you should be able to see if user is getting set to anything.
I was working on something like that and found that user wasn't picking up with my decoder. I ended up switching to using a match instead.
If you run the log entry through ossec-logtest you should be able to see if user is getting set to anything.