<decoder name="freeradius">
<program_name>^freeradius</program_name>
</decoder>
<decoder name="freeradius_stop">
<parent>freeradius</parent>
<prematch>^Stopping</prematch>
<regex offset="after_prematch">^ FreeRADIUS\s(\S+)\s(\S+)</regex>
</decoder>
<decoder name="freeradius_start">
<parent>freeradius</parent>
<prematch>^Starting</prematch>
<regex offset="after_prematch">^ FreeRADIUS\s(\S+)\s(\S+)</regex>
</decoder>
and when I restarted ossec in logs I see :
2016/06/17 13:40:29 ossec-analysisd(2107): ERROR: Decoder configuration error: 'freeradius_stop'.
2016/06/17 13:40:29 ossec-testrule(1202): ERROR: Configuration error at '/etc/local_decoder.xml'. Exiting.
I created this decoder for this logs:
2016 Jun 16 16:44:26 (radius) 172.16.12.135->/var/log/syslog Jun 16 16:44:24 radius freeradius[29059]: Stopping FreeRADIUS daemon: freeradius.
2016 Jun 16 16:44:26 (radius) 172.16.12.135->/var/log/syslog Jun 16 16:44:24 radius freeradius[29063]: Starting FreeRADIUS daemon: freeradius.
I checked ossec-control file and script is ok.