parse docker header

This commit is contained in:
Kameron Kenny 2024-06-19 17:01:28 -04:00
parent ba51bbdcee
commit 496e167184
No known key found for this signature in database
GPG Key ID: E5006629839D2276
3 changed files with 17 additions and 32 deletions

View File

@ -1,7 +1,7 @@
FROM debian:latest FROM debian:latest
MAINTAINER Kameron Kenny <kkenny379@gmail.com> MAINTAINER Kameron Kenny <kkenny379@gmail.com>
LABEL version="20240619.1.5" LABEL version="20240619.1.6"
LABEL description="Debian Based syslog-ng" LABEL description="Debian Based syslog-ng"
RUN apt-get update RUN apt-get update

View File

@ -1,5 +1,4 @@
filter f_bind9_primary { message("bind9-primary"); }; filter f_bind9 { message("bind9"); };
filter f_bind9_secondary { message("bind9-secondary"); };
rewrite r_docker_image { rewrite r_docker_image {
subst("^5000/tlp/", "image:", value("MESSAGE")); subst("^5000/tlp/", "image:", value("MESSAGE"));
@ -15,17 +14,23 @@ rewrite r_docker_image {
parser p_bind_message { parser p_bind_message {
csv-parser( csv-parser(
prefix("bind9.")
flags(strip-whitespace) flags(strip-whitespace)
delimiters(" ") delimiters(" ")
columns("docker_header", "date", "time", "client.header", "client.object_id", "client.ip_port", "client.request", "query.header", "query.request", "query.class", "query.type", "query.flags") columns("docker_header", "bind9.log.date", "bind9.log.time", "bind9.client.header", "bind9.client.object_id", "bind9.client.ip_port", "bind9.client.request", "bind9.query.header", "bind9.query.request", "bind9.query.class", "bind9.query.type", "bind9.query.flags")
); );
}; };
parser p_bind_kv { rewrite r_docker_header {
kv-parser( subst("5000\/tlp\/", "", value("docker_header"));
prefix("bind9.") subst("(:|\/|\[|\])", " ", value("docker_header"));
value-separator(":") };
parser p_docker_header {
csv-parser(
prefix("docker_header")
flags(strip-whitespace)
delimiters(" ")
columns("docker.image.name", "docker.image.version", "docker.container.name", "docker.container.pid")
); );
}; };
@ -55,18 +60,8 @@ log {
source(s_network_udp); source(s_network_udp);
filter(f_bind9_primary); filter(f_bind9_primary);
parser(p_bind_message); parser(p_bind_message);
# rewrite(r_docker_image); rewrite(r_docker_header);
#parser(p_bind_kv); parser(p_docker_header);
destination(d_bind_logs);
flags(final);
};
log {
source(s_network_udp);
filter(f_bind9_secondary);
parser(p_bind_message);
# rewrite(r_docker_image);
# parser(p_bind_kv);
destination(d_bind_logs); destination(d_bind_logs);
flags(final); flags(final);
}; };

View File

@ -10,18 +10,8 @@ services:
syslog-ng: syslog-ng:
build: build:
dockerfile: Dockerfile dockerfile: Dockerfile
image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.5 image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.6
container_name: syslog-ng container_name: syslog-ng
#environment:
#- TZ:America/Indianapolis
#- PUID=0
#- PGID=0
#volumes:
#- syslog-ng_logs:/var/log
#ports:
#- 514:5514/udp
#- 601:6601/tcp
#- 6514:6514/tcp
restart: unless-stopped restart: unless-stopped
networks: networks:
infra_dev_net: infra_dev_net: