<!-- Ignore rule 18139 -->
<rule id="100117" level="0">
<if_sid>18139</if_sid>
<options>no_log</options>
<regex>User name:\s+\.*\$\s+</regex>
<description>Windows login failure for workstation - user name ends in $ (ignored)</description>
</rule>
[root@ossec etc]# /opt/ossec/bin/ossec-logtest
2014/07/01 08:53:27 ossec-testrule: INFO: Reading local decoder file.
2014/07/01 08:53:27 ossec-analysisd(1227): ERROR: Error applying XML variables 'rules//local_rules.xml': XMLERR: Unknown variable: '\s+'..
2014/07/01 08:53:27 ossec-testrule(1220): ERROR: Error loading the rules: 'local_rules.xml'.