/^su: BAD SU (\S+) to (\S+) on (\S+)$/ %PROC.NAME=su;SRC.USR;DST.USR;PROC.TTY;MSG=bad su (wrong password)%
/^newsyslog\[(\d+)\]: logfile turned over/ %SKIP%
/^kernel: (.*)/ %(kernel)%