diff --git a/Dockerfile b/Dockerfile index 7ce6dff..bc0d704 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241029144357" +LABEL version="20241029145027" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 4ccc43f..f6b9a75 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -8,6 +8,10 @@ parser p_suricata_stats_json { ); }; +rewrite r_set_message { + set("extracted", value("MESSAGE")); +}; + destination d_nas81_suricata { elasticsearch-http( index("nas81-suricata") @@ -30,7 +34,7 @@ destination d_nas81_suricata_stats { format-json --scope rfc5424 --scope dot-nv-pairs --scope nv-pairs --exclude DATE @timestamp=${ISODATE} - --exclude MESSAGE + MESSAGE="extracted" )\n" ) persist-name("d_nas81_suricata_stats") @@ -44,7 +48,7 @@ destination d_file_suricata { format-json --scope rfc5424 --scope dot-nv-pairs --scope nv-pairs --exclude DATE @timestamp=${ISODATE} - --exclude MESSAGE + MESSAGE="extracted" )\n" ) ); diff --git a/docker-compose.yml b/docker-compose.yml index a0fef78..d18822c 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029144357 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029145027 container_name: syslog-ng restart: unless-stopped networks: