From 3e9174f40bb4c833782a1dff019adf8b1ab1e02b Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Wed, 30 Oct 2024 09:22:13 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/unifi.conf | 10 +++------- docker-compose.yml | 2 +- 3 files changed, 5 insertions(+), 9 deletions(-) diff --git a/Dockerfile b/Dockerfile index e7dd683..b9f6ea7 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241030092044" +LABEL version="20241030092213" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/unifi.conf b/config/syslog-ng.conf.d/unifi.conf index 15dafd8..82e4356 100644 --- a/config/syslog-ng.conf.d/unifi.conf +++ b/config/syslog-ng.conf.d/unifi.conf @@ -48,12 +48,6 @@ parser p_suricata_src_ip_geoip2_city { ); }; -template t_elastic { - format-json --scope rfc5424 --scope dot-nv-pairs - --rekey .* --shift 1 --scope nv-pairs - --exclude DATE @timestamp=${ISODATE} -}; - destination d_unifi_fw { file("/var/log/unifi_fw.log"); }; destination d_unifi_suricata { @@ -63,7 +57,9 @@ destination d_unifi_suricata { user("elastic") password("forty6and2") url("http://pi501.in.thelinuxpro.net:9200/_bulk") - template(t_elastic) + template("$(format-json --scope rfc5424 --scope dot-nv-pairs + --rekey .* --shift 1 --scope nv-pairs + --exclude DATE @timestamp=${ISODATE})") persist-name("d_unifi_suricata") ); }; diff --git a/docker-compose.yml b/docker-compose.yml index afb362a..324a2ab 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241030092044 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241030092213 container_name: syslog-ng restart: unless-stopped networks: