From 921e47c7d1980ce3a8cd7d328e8cc4978f9b5e1f Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Fri, 14 Jun 2024 10:56:01 -0400 Subject: [PATCH] ES Teamplate firewall --- Dockerfile | 2 +- config/syslog-ng.conf | 10 +++++++++- docker-compose.yml | 2 +- 3 files changed, 11 insertions(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 8ad13cb..185a3ba 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM lscr.io/linuxserver/syslog-ng:latest -LABEL version="20240614.1.1" +LABEL version="20240614.1.2" LABEL description="syslog-ng" RUN mkdir -p /config diff --git a/config/syslog-ng.conf b/config/syslog-ng.conf index 04c89ef..ed1f4cb 100644 --- a/config/syslog-ng.conf +++ b/config/syslog-ng.conf @@ -35,7 +35,15 @@ destination d_unifi_firewall { url("http://pi501.in.thelinuxpro.net:9200/_bulk") template("$(format-json --scope rfc5424 --scope dot-nv-pairs --rekey .* --shift 1 --scope nv-pairs - --exclude DATE @timestamp=${ISODATE})") + --exclude DATE @timestamp=${ISODATE} + DESCRIPTION=$(DESC) + INTERFACE_IN=$(IN) + INTERFACE_OUT=$(OUT) + IP_SOURCE=$(SRC) + IP_DESTINATION=$(DST) + PROTOCOL=$(PROTO) + PORT_SOURCE=$(SPT) + PORT_DESTINATION=$(DPT))") persist-name("d_unifi_firewall") ); }; diff --git a/docker-compose.yml b/docker-compose.yml index f0814d3..970aceb 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240614.1.1 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240614.1.2 container_name: syslog-ng environment: - PUID=0