From debc4c5dd61e755770f86ba1598c471cee1a07e8 Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Mon, 28 Oct 2024 17:19:52 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 12 ++++-------- docker-compose.yml | 2 +- 3 files changed, 6 insertions(+), 10 deletions(-) diff --git a/Dockerfile b/Dockerfile index 3fda788..4193f40 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241028170659" +LABEL version="20241028171952" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 0b1e081..57aba92 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -2,13 +2,8 @@ filter f_nas81_suricata { match("suricata" value("PROGRAM")); }; filter f_nas81_host { match("nas81" value("HOST")); }; filter f_nas81_suricata_stats { match("stats" value("MESSAGE")); }; -template t_json { - template("${MESSAGE}\n"); - template-escape(no); -}; - parser p_suricata_stats_json { - json-parser(prefix("suricata.stats.")); + json-parser(prefix(".suricata.stats.")); }; destination d_nas81_suricata { @@ -28,9 +23,10 @@ destination d_nas81_suricata_stats { index("nas81") type("") url("http://pi501.in.thelinuxpro.net:9200/_bulk") - template("$(format-json --scope nv_pairs,core,syslog,all_macros,selected_macros,everything + template("$(format-json --scope rfc5424 --scope dot-nv-pairs + --rekey .* --shift 1 --scope nv-pairs --exclude DATE @timestamp=${ISODATE})") - persist-name("d_nas81") + persist-name("d_nas81_suricata_stats") ); }; diff --git a/docker-compose.yml b/docker-compose.yml index 50fc536..7a42743 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241028170659 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241028171952 container_name: syslog-ng restart: unless-stopped networks: