Here's a pattern that has one example with missing values:
98c131b414229ec1437da915f07c791da47bd80b:
ruleset: systemd
ruleclass: sequence
patterns:
- '@ESTRING:action: @User Manager for UID @NUMBER:integer@.'
examples:
- program: systemd
test_message: Stopped User Manager for UID 0.
test_values: {}
- program: systemd
test_message: Stopped User Manager for UID 9991.
test_values:
action: Stopped
integer: "9991"
- program: systemd
test_message: Stopped User Manager for UID 300.
test_values:
action: Stopped
integer: "300"
Maybe due to an ill test that returns false for a value of 0 ?