diff --git a/Dockerfile b/Dockerfile index 776c750..6f7f3d9 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241029143250" +LABEL version="20241029144001" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index b4783eb..6d2f037 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -4,7 +4,7 @@ filter f_nas81_suricata_stats { match("suricata-stats" value("PROGRAM")); }; parser p_suricata_stats_json { json-parser( - prefix("suricata.stats.") + prefix("suricata.") ); }; @@ -25,20 +25,28 @@ destination d_nas81_suricata_stats { index("nas81") type("") url("http://pi501.in.thelinuxpro.net:9200/_bulk") - template("$(format-json --scope rfc5424 --scope dot-nv-pairs - --rekey .* --shift 1 --scope nv-pairs - --exclude DATE @timestamp=${ISODATE} - --exclude MESSAGE delimiter('\n'))") + template( + "$( + format-json --scope rfc5424 --scope dot-nv-pairs + --rekey .* --shift 1 --scope nv-pairs + --exclude DATE @timestamp=${ISODATE} + --exclude MESSAGE + )\n" + ) persist-name("d_nas81_suricata_stats") ); }; destination d_file_suricata { file("/var/log/suricata.log" - template("$(format-json --scope rfc5424 --scope dot-nv-pairs - --rekey .* --shift 1 --scope nv-pairs - --exclude DATE @timestamp=${ISODATE} - --exclude MESSAGE delimiter('\n'))") + template( + "$( + format-json --scope rfc5424 --scope dot-nv-pairs + --rekey .* --shift 1 --scope nv-pairs + --exclude DATE @timestamp=${ISODATE} + --exclude MESSAGE + )\n" + ) ); }; diff --git a/docker-compose.yml b/docker-compose.yml index 70911e9..ecdae7f 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029143250 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029144001 container_name: syslog-ng restart: unless-stopped networks: