From db6aa12f536dbe24488cbb338dbcf51e43cfc717 Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Tue, 29 Oct 2024 14:30:33 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 6 +++--- docker-compose.yml | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/Dockerfile b/Dockerfile index dcf552b..c36b914 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241029142406" +LABEL version="20241029143033" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 3e3285f..92ca964 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -4,7 +4,7 @@ filter f_nas81_suricata_stats { match("suricata-stats" value("PROGRAM")); }; parser p_suricata_stats_json { json-parser( - prefix("suricata.") + prefix("suricata.stats.") ); }; @@ -28,7 +28,7 @@ destination d_nas81_suricata_stats { template("$(format-json --scope rfc5424 --scope dot-nv-pairs --rekey .* --shift 1 --scope nv-pairs --exclude DATE @timestamp=${ISODATE} - --exclude MESSAGE)") + --exclude MESSAGE delimiter('\n')") persist-name("d_nas81_suricata_stats") ); }; @@ -38,7 +38,7 @@ destination d_file_suricata { template("$(format-json --scope rfc5424 --scope dot-nv-pairs --rekey .* --shift 1 --scope nv-pairs --exclude DATE @timestamp=${ISODATE} - --exclude MESSAGE)") + --exclude MESSAGE delimiter('\n')") ); }; diff --git a/docker-compose.yml b/docker-compose.yml index 4e16398..9ac6957 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029142406 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029143033 container_name: syslog-ng restart: unless-stopped networks: