From e8e8f2011c39fcc5c92b774be54e748c45c1c2ad Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Fri, 21 Jun 2024 15:23:20 -0400 Subject: [PATCH] request parsing --- Dockerfile | 2 +- config/syslog-ng.conf.d/nginx.conf | 10 ++++++++++ docker-compose.yml | 2 +- 3 files changed, 12 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 0164e81..12dc8fe 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20240621.2.2" +LABEL version="20240621.2.3" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/nginx.conf b/config/syslog-ng.conf.d/nginx.conf index 4108b1b..147fdff 100644 --- a/config/syslog-ng.conf.d/nginx.conf +++ b/config/syslog-ng.conf.d/nginx.conf @@ -26,6 +26,15 @@ parser p_nginx_docker_header { ); }; +parser p_nginx_request_header { + csv-parser( + template("${nginx.request}") + flags(strip-whitespace) + delimiters(" ") + columns("nginx.request.method", "nginx.request.string", "nginx.request.protocol") + ); +}; + parser p_nginx_client_ip_geoip2_city { geoip2( "${nginx.client.ip}", @@ -54,6 +63,7 @@ log { parser(p_nginx_message); rewrite(r_nginx_docker_header); parser(p_nginx_docker_header); + parser(p_nginx_request_header); parser(p_nginx_client_ip_geoip2_city); destination(d_nginx_logs); flags(final); diff --git a/docker-compose.yml b/docker-compose.yml index 09b4faa..b159346 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240621.2.2 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240621.2.3 container_name: syslog-ng restart: unless-stopped networks: