This commit is contained in:
Kameron Kenny 2024-10-24 18:18:56 -04:00
parent ddaed1069d
commit d0c710425a
No known key found for this signature in database
GPG Key ID: E5006629839D2276
3 changed files with 5 additions and 22 deletions

View File

@ -1,7 +1,7 @@
FROM debian:latest FROM debian:latest
MAINTAINER Kameron Kenny <kkenny379@gmail.com> MAINTAINER Kameron Kenny <kkenny379@gmail.com>
LABEL version="20241024.1.2" LABEL version="20241024.1.3"
LABEL description="Debian Based syslog-ng" LABEL description="Debian Based syslog-ng"
RUN apt-get update RUN apt-get update

View File

@ -1,22 +1,5 @@
filter f_nas81_suricata { match("suricata" value("PROGRAM")); }; filter f_nas81_suricata { match("suricata" value("PROGRAM")); };
filter f_nas81_host { match("nas81" value("HOST")); }; filter f_nas81_host { match("nas81" value("HOST")); };
parser p_kv { kv-parser(prefix("kv.")); };
parser p_suricata_dest_ip_geoip2_city {
geoip2(
"${suricata.dest_ip}",
prefix( "geoip2.destination." )
database( "/config/GeoIP/GeoLite2-City.mmdb" )
);
};
parser p_suricata_src_ip_geoip2_city {
geoip2(
"${suricata.src_ip}",
prefix( "geoip2.source." )
database( "/config/GeoIP/GeoLite2-City.mmdb" )
);
};
destination d_nas81_suricata { destination d_nas81_suricata {
elasticsearch-http( elasticsearch-http(
@ -37,9 +20,9 @@ destination d_file_suricata { file("/var/log/suricata.log"); };
log { log {
source(s_network_udp); source(s_network_udp);
filter(f_nas81_host); filter(f_nas81_host);
#parser(p_suricata_json); parser(p_suricata_json);
#parser(p_suricata_src_ip_geoip2_city); parser(p_suricata_src_ip_geoip2_city);
#parser(p_suricata_dest_ip_geoip2_city); parser(p_suricata_dest_ip_geoip2_city);
destination(d_file_suricata); destination(d_file_suricata);
destination(d_nas81_suricata); destination(d_nas81_suricata);
flags(final); flags(final);

View File

@ -10,7 +10,7 @@ services:
syslog-ng: syslog-ng:
build: build:
dockerfile: Dockerfile dockerfile: Dockerfile
image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:241024.1.2 image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:241024.1.3
container_name: syslog-ng container_name: syslog-ng
restart: unless-stopped restart: unless-stopped
networks: networks: