From 2cbc91e28c3e8aae78f9afb4da77aa66dc8acc84 Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Mon, 28 Oct 2024 13:36:05 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 10 +++------- docker-compose.yml | 2 +- 3 files changed, 5 insertions(+), 9 deletions(-) diff --git a/Dockerfile b/Dockerfile index c423065..9cedf3e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241028.1.4" +LABEL version="20241028.1.5" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 747f29f..efbd503 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -23,14 +23,12 @@ destination d_nas81_suricata { ); }; -destination d_nas81 { +destination d_nas81_suricata_stats { elasticsearch-http( index("nas81") type("") url("http://pi501.in.thelinuxpro.net:9200/_bulk") - template("$(format-json --scope rfc5424 --scope dot-nv-pairs - --rekey .* --shift 1 --scope nv-pairs - --exclude DATE @timestamp=${ISODATE})") + template("$(format-json --scope rfc5424) persist-name("d_nas81") ); }; @@ -43,9 +41,7 @@ log { filter(f_suricata); filter(f_nas81_suricata_stats); parser(p_suricata_stats_json); - parser(p_suricata_src_ip_geoip2_city); - parser(p_suricata_dest_ip_geoip2_city); - destination(d_nas81_suricata); + destination(d_nas81_suricata_stats); flags(final); }; diff --git a/docker-compose.yml b/docker-compose.yml index 58b9bd4..9f6766e 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:241028.1.4 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:241028.1.5 container_name: syslog-ng restart: unless-stopped networks: