From 16f511d39a743273aeeb0fc0ea00a45ec0dfad9b Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Fri, 21 Jun 2024 16:42:31 -0400 Subject: [PATCH] fix --- Dockerfile | 2 +- config/syslog-ng.conf.d/nginx.conf | 9 +++++---- docker-compose.yml | 2 +- 3 files changed, 7 insertions(+), 6 deletions(-) diff --git a/Dockerfile b/Dockerfile index 6376e21..1d938a3 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20240621.2.6" +LABEL version="20240621.2.7" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nginx.conf b/config/syslog-ng.conf.d/nginx.conf index 7b6deaa..1674d3c 100644 --- a/config/syslog-ng.conf.d/nginx.conf +++ b/config/syslog-ng.conf.d/nginx.conf @@ -7,7 +7,7 @@ parser p_nginx_message { flags(strip-whitespace) delimiters(" ") quote-pairs('""[]') - columns("docker", "nginx.client.ip", "nginx.ident", "nginx.auth", "nginx.timestamp", "nginx.request", "nginx.response", "nginx.bytes", "nginx.referrer", "nginx.agent") + columns("docker", "nginx.client.ip", "nginx.ident", "nginx.auth", "nginx.timestamp", "nginx_request", "nginx.response", "nginx.bytes", "nginx.referrer", "nginx.agent") ); }; @@ -29,10 +29,10 @@ parser p_nginx_docker_header { parser p_nginx_request_header { csv-parser( - template("${nginx.request}") + template("${nginx_request}") flags(strip-whitespace) delimiters(" ") - columns("nginx.request.method", "nginx.request.string", "nginx.request.protocol") + columns("nginx.request_method", "nginx.request_string", "nginx.request_protocol") ); }; @@ -63,9 +63,10 @@ log { filter(f_nginx); filter(f_nginx_priority_info); parser(p_nginx_message); + parser(p_nginx_request_header); + parser(p_nginx_request_header); rewrite(r_nginx_docker_header); parser(p_nginx_docker_header); - parser(p_nginx_request_header); parser(p_nginx_client_ip_geoip2_city); destination(d_nginx_logs); flags(final); diff --git a/docker-compose.yml b/docker-compose.yml index 68ab604..df477fe 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240621.2.6 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240621.2.7 container_name: syslog-ng restart: unless-stopped networks: