From 8b3cf236ad0f53d95632f7d7bad3f331781b7f2b Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Wed, 19 Jun 2024 17:44:06 -0400 Subject: [PATCH] relabel --- Dockerfile | 2 +- config/syslog-ng.conf.d/bind-dns.conf | 11 +++++++---- docker-compose.yml | 2 +- 3 files changed, 9 insertions(+), 6 deletions(-) diff --git a/Dockerfile b/Dockerfile index ea02018..f8941df 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20240619.1.8" +LABEL version="20240619.1.9" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/bind-dns.conf b/config/syslog-ng.conf.d/bind-dns.conf index b29c442..56bd323 100644 --- a/config/syslog-ng.conf.d/bind-dns.conf +++ b/config/syslog-ng.conf.d/bind-dns.conf @@ -16,18 +16,21 @@ parser p_bind_message { csv-parser( flags(strip-whitespace) delimiters(" ") - columns("docker_header", "bind9.log.date", "bind9.log.time", "bind9.client.header", "bind9.client.object_id", "bind9.client.ip_port", "bind9.client.request", "bind9.query.header", "bind9.query.request", "bind9.query.class", "bind9.query.type", "bind9.query.flags") + columns("docker", "bind9.log.date", "bind9.log.time", "bind9.client.header", "bind9.client.object_id", "bind9.client.ip_port", "bind9.client.request", "bind9.query.header", "bind9.query.request", "bind9.query.class", "bind9.query.type", "bind9.query.flags") ); }; rewrite r_docker_header { - subst("5000\/tlp\/", "", value("docker_header")); - subst('(:|\/|\[|\])', " ", value("docker_header")); + subst("5000\/tlp\/", "", value("docker")); + subst(":", " ", value("docker")); + subst(":", " ", value("docker")); + subst("\/", " ", value("docker")); + subst('\[', " ", value("docker")); + subst('\]', " ", value("docker")); }; parser p_docker_header { csv-parser( - prefix("docker_header") flags(strip-whitespace) delimiters(" ") columns("docker.image.name", "docker.image.version", "docker.container.name", "docker.container.pid") diff --git a/docker-compose.yml b/docker-compose.yml index 1525fe1..6731b0a 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.8 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.9 container_name: syslog-ng restart: unless-stopped networks: