$ 0 0 ntp server (?!10.1.1.1).* This will find ntp server with any other IP address. Use this as a rule, alert critical if found.