From 4ffde3b26b0bf6d74123a78050baa40cf164f5ca Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Tue, 29 Oct 2024 15:06:38 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 12 ++++++++++-- docker-compose.yml | 2 +- 3 files changed, 12 insertions(+), 4 deletions(-) diff --git a/Dockerfile b/Dockerfile index 56e36c2..8aa88f4 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241029145218" +LABEL version="20241029150638" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 3e01144..16c7fc8 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -41,8 +41,8 @@ destination d_nas81_suricata_stats { ); }; -destination d_file_suricata { - file("/var/log/suricata.log" +destination d_file_suricata_stats { + file("/var/log/suricata_stats.log" template( "$( format-json --scope rfc5424 --scope dot-nv-pairs @@ -54,6 +54,14 @@ destination d_file_suricata { ); }; +destination d_file_suricata { + file("/var/log/suricata.log" + template("$(format-json --scope rfc5424 --scope dot-nv-pairs + --rekey .* --shift 1 --scope nv-pairs + --exclude DATE @timestamp=${ISODATE})") + ); +}; + log { source(s_network_udp); filter(f_nas81_host); diff --git a/docker-compose.yml b/docker-compose.yml index 831a64f..34941aa 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029145218 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029150638 container_name: syslog-ng restart: unless-stopped networks: