This commit is contained in:
Kameron Kenny 2024-10-29 16:09:38 -04:00
parent f9bd09261e
commit e3570ec50d
No known key found for this signature in database
GPG Key ID: E5006629839D2276
3 changed files with 12 additions and 2 deletions

View File

@ -1,7 +1,7 @@
FROM debian:latest FROM debian:latest
MAINTAINER Kameron Kenny <kkenny379@gmail.com> MAINTAINER Kameron Kenny <kkenny379@gmail.com>
LABEL version="20241029160014" LABEL version="20241029160938"
LABEL description="Debian Based syslog-ng" LABEL description="Debian Based syslog-ng"
RUN apt-get update RUN apt-get update

View File

@ -8,6 +8,12 @@ parser p_suricata_stats_json {
); );
}; };
parser p_no_header {
syslog-parser(
flags(no-header)
);
};
rewrite r_set_message { rewrite r_set_message {
set("extracted", value("MESSAGE")); set("extracted", value("MESSAGE"));
}; };
@ -36,6 +42,8 @@ destination d_nas81_suricata_stats {
template( template(
"$( "$(
format-json --scope rfc5424 format-json --scope rfc5424
--scope dot-nv-pairs
--scope nv-pairs
--exclude DATE @timestamp=${ISODATE} --exclude DATE @timestamp=${ISODATE}
MESSAGE='extracted' MESSAGE='extracted'
)\n" )\n"
@ -49,6 +57,8 @@ destination d_file_suricata_stats {
template( template(
"$( "$(
format-json --scope rfc5424 format-json --scope rfc5424
--scope dot-nv-pairs
--scope nv-pairs
--exclude DATE @timestamp=${ISODATE} --exclude DATE @timestamp=${ISODATE}
MESSAGE='extracted' MESSAGE='extracted'
)\n" )\n"

View File

@ -10,7 +10,7 @@ services:
syslog-ng: syslog-ng:
build: build:
dockerfile: Dockerfile dockerfile: Dockerfile
image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029160014 image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:20241029160938
container_name: syslog-ng container_name: syslog-ng
restart: unless-stopped restart: unless-stopped
networks: networks: