From e3570ec50d22ace95267c70ee8e6ac11d5c7a7df Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Tue, 29 Oct 2024 16:09:38 -0400 Subject: [PATCH] stats --- Dockerfile | 2 +- config/syslog-ng.conf.d/nas81.conf | 10 ++++++++++ docker-compose.yml | 2 +- 3 files changed, 12 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 573d8e4..7482139 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20241029160014" +LABEL version="20241029160938" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nas81.conf b/config/syslog-ng.conf.d/nas81.conf index 71c7982..6c4131e 100644 --- a/config/syslog-ng.conf.d/nas81.conf +++ b/config/syslog-ng.conf.d/nas81.conf @@ -8,6 +8,12 @@ parser p_suricata_stats_json { ); }; +parser p_no_header { + syslog-parser( + flags(no-header) + ); +}; + rewrite r_set_message { set("extracted", value("MESSAGE")); }; @@ -36,6 +42,8 @@ destination d_nas81_suricata_stats { template( "$( format-json --scope rfc5424 + --scope dot-nv-pairs + --scope nv-pairs --exclude DATE @timestamp=${ISODATE} MESSAGE='extracted' )\n" @@ -49,6 +57,8 @@ destination d_file_suricata_stats { template( "$( format-json --scope rfc5424 + --scope dot-nv-pairs + --scope nv-pairs --exclude DATE @timestamp=${ISODATE} MESSAGE='extracted' )\n" diff --git a/docker-compose.yml b/docker-compose.yml index bd8eb14..508e727 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029160014 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029160938 container_name: syslog-ng restart: unless-stopped networks: