From d0c710425a40811c984a644f0d1554986cac0ea7 Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Thu, 24 Oct 2024 18:18:56 -0400 Subject: [PATCH] file --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 23 +++-------------------- docker-compose.yml | 2 +- 3 files changed, 5 insertions(+), 22 deletions(-) diff --git a/Dockerfile b/Dockerfile index d6066d9..9c76bab 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241024.1.2" +LABEL version="20241024.1.3" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 97a8139..44e9f8d 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -1,22 +1,5 @@ filter f_nas81_suricata { match("suricata" value("PROGRAM")); }; filter f_nas81_host { match("nas81" value("HOST")); }; -parser p_kv { kv-parser(prefix("kv.")); }; - -parser p_suricata_dest_ip_geoip2_city { - geoip2( - "${suricata.dest_ip}", - prefix( "geoip2.destination." ) - database( "/config/GeoIP/GeoLite2-City.mmdb" ) - ); -}; - -parser p_suricata_src_ip_geoip2_city { - geoip2( - "${suricata.src_ip}", - prefix( "geoip2.source." ) - database( "/config/GeoIP/GeoLite2-City.mmdb" ) - ); -}; destination d_nas81_suricata { elasticsearch-http( @@ -37,9 +20,9 @@ destination d_file_suricata { file("/var/log/suricata.log"); }; log { source(s_network_udp); filter(f_nas81_host); - #parser(p_suricata_json); - #parser(p_suricata_src_ip_geoip2_city); - #parser(p_suricata_dest_ip_geoip2_city); + parser(p_suricata_json); + parser(p_suricata_src_ip_geoip2_city); + parser(p_suricata_dest_ip_geoip2_city); destination(d_file_suricata); destination(d_nas81_suricata); flags(final); diff --git a/docker-compose.yml b/docker-compose.yml index 049fe52..4782728 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:241024.1.2 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:241024.1.3 container_name: syslog-ng restart: unless-stopped networks: