parse docker header

This commit is contained in:
Kameron Kenny 2024-06-19 17:01:28 -04:00
parent ba51bbdcee
commit 496e167184
No known key found for this signature in database
GPG Key ID: E5006629839D2276
3 changed files with 17 additions and 32 deletions

View File

@ -1,7 +1,7 @@
FROM debian:latest
MAINTAINER Kameron Kenny <kkenny379@gmail.com>
LABEL version="20240619.1.5"
LABEL version="20240619.1.6"
LABEL description="Debian Based syslog-ng"
RUN apt-get update

View File

@ -1,5 +1,4 @@
filter f_bind9_primary { message("bind9-primary"); };
filter f_bind9_secondary { message("bind9-secondary"); };
filter f_bind9 { message("bind9"); };
rewrite r_docker_image {
subst("^5000/tlp/", "image:", value("MESSAGE"));
@ -15,17 +14,23 @@ rewrite r_docker_image {
parser p_bind_message {
csv-parser(
prefix("bind9.")
flags(strip-whitespace)
delimiters(" ")
columns("docker_header", "date", "time", "client.header", "client.object_id", "client.ip_port", "client.request", "query.header", "query.request", "query.class", "query.type", "query.flags")
columns("docker_header", "bind9.log.date", "bind9.log.time", "bind9.client.header", "bind9.client.object_id", "bind9.client.ip_port", "bind9.client.request", "bind9.query.header", "bind9.query.request", "bind9.query.class", "bind9.query.type", "bind9.query.flags")
);
};
parser p_bind_kv {
kv-parser(
prefix("bind9.")
value-separator(":")
rewrite r_docker_header {
subst("5000\/tlp\/", "", value("docker_header"));
subst("(:|\/|\[|\])", " ", value("docker_header"));
};
parser p_docker_header {
csv-parser(
prefix("docker_header")
flags(strip-whitespace)
delimiters(" ")
columns("docker.image.name", "docker.image.version", "docker.container.name", "docker.container.pid")
);
};
@ -55,18 +60,8 @@ log {
source(s_network_udp);
filter(f_bind9_primary);
parser(p_bind_message);
# rewrite(r_docker_image);
#parser(p_bind_kv);
destination(d_bind_logs);
flags(final);
};
log {
source(s_network_udp);
filter(f_bind9_secondary);
parser(p_bind_message);
# rewrite(r_docker_image);
# parser(p_bind_kv);
rewrite(r_docker_header);
parser(p_docker_header);
destination(d_bind_logs);
flags(final);
};

View File

@ -10,18 +10,8 @@ services:
syslog-ng:
build:
dockerfile: Dockerfile
image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.5
image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.6
container_name: syslog-ng
#environment:
#- TZ:America/Indianapolis
#- PUID=0
#- PGID=0
#volumes:
#- syslog-ng_logs:/var/log
#ports:
#- 514:5514/udp
#- 601:6601/tcp
#- 6514:6514/tcp
restart: unless-stopped
networks:
infra_dev_net: