diff --git a/Dockerfile b/Dockerfile index a7d9f69..d2e28c3 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241028174708" +LABEL version="20241028175549" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 060f659..00205f5 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -6,6 +6,10 @@ parser p_suricata_stats_json { json-parser(prefix(".suricata.stats.")); }; +parser p_suricata_stats_stats { + json-parser( "${MESSAGE.stats}" ); +}; + destination d_nas81_suricata { elasticsearch-http( index("nas81-suricata") @@ -36,6 +40,7 @@ log { filter(f_nas81_host); filter(f_suricata); filter(f_nas81_suricata_stats); + parser(p_suricata_stats_stats); parser(p_suricata_stats_json); destination(d_nas81_suricata_stats); flags(final); diff --git a/docker-compose.yml b/docker-compose.yml index 5139904..22eaf90 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241028174708 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241028175549 container_name: syslog-ng restart: unless-stopped networks: