alert syslog $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET] Administrator removed logs"; content: "32013 type="; pcre: "/cleared|deleted|removed/"; classtype: configuration-change; reference: url,wiki.quadrantsec.com/bin/view/Main/5000924; sid: 5000924; rev:2;)
-- Main.Sagan-Wiki-Add - 2015-10-21
New revisions of 5000924 will be below...
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET] Administrator removed logs"; content: "32013 type="; meta_content: "%sagan%",cleared,deleted,removed; classtype: configuration-change; reference: url,wiki.quadrantsec.com/bin/view/Main/5000924; sid: 5000924; rev:4;)
-- Main.Sagan-Wiki-Add - 2021-4-12