From 38087972a5f5acef056f4472c196d7d61c421fa7 Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Mon, 28 Oct 2024 18:01:22 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 8 ++------ docker-compose.yml | 2 +- 3 files changed, 4 insertions(+), 8 deletions(-) diff --git a/Dockerfile b/Dockerfile index 437dd63..598faa1 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241028175819" +LABEL version="20241028180122" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 6ae0f82..c328933 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -3,11 +3,8 @@ filter f_nas81_host { match("nas81" value("HOST")); }; filter f_nas81_suricata_stats { match("stats" value("MESSAGE")); }; parser p_suricata_stats_json { - json-parser(prefix(".suricata.stats.")); -}; - -parser p_suricata_stats_stats { - json-parser( "${MESSAGE}" ); + marker("stats:") + json-parser(prefix("suricata.stats.")); }; destination d_nas81_suricata { @@ -40,7 +37,6 @@ log { filter(f_nas81_host); filter(f_suricata); filter(f_nas81_suricata_stats); - parser(p_suricata_stats_stats); parser(p_suricata_stats_json); destination(d_nas81_suricata_stats); flags(final); diff --git a/docker-compose.yml b/docker-compose.yml index ff42760..0f41a92 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241028175819 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241028180122 container_name: syslog-ng restart: unless-stopped networks: