From 051f4469eddf4d199d41f73912150209682d0c62 Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Tue, 29 Oct 2024 16:31:54 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 7 ++++++- docker-compose.yml | 2 +- 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index a278953..5c63086 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241029162807" +LABEL version="20241029163154" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 76dc008..64675ee 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -8,6 +8,10 @@ parser p_suricata_stats_json { ); }; +parser p_stats_json { + json-parser(); +}; + parser p_no_header { syslog-parser( flags(no-header) @@ -82,10 +86,11 @@ destination d_file_suricata { log { source(s_network_udp); + parser(p_no_parse); filter(f_nas81_host); filter(f_nas81_suricata_stats); + parser(p_stats_json); #parser(p_no_header); - parser(p_no_parse); #parser(p_suricata_stats_json); # rewrite(r_stats_rename); destination(d_nas81_suricata_stats); diff --git a/docker-compose.yml b/docker-compose.yml index 52f98e5..a82d790 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029162807 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029163154 container_name: syslog-ng restart: unless-stopped networks: