From e9f93e474b90ad3fe2b60c06aaea3f4a885072b9 Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Wed, 19 Jun 2024 20:10:33 -0400 Subject: [PATCH] split client ip port --- Dockerfile | 2 +- config/syslog-ng.conf.d/bind-dns.conf | 13 ++++++++++++- docker-compose.yml | 2 +- 3 files changed, 14 insertions(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 7ede205..771a15d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,7 @@ FROM debian:latest MAINTAINER Kameron Kenny -LABEL version="20240619.1.10" +LABEL version="20240619.1.11" LABEL description="Debian Based syslog-ng" RUN apt-get update diff --git a/config/syslog-ng.conf.d/bind-dns.conf b/config/syslog-ng.conf.d/bind-dns.conf index ded7627..9817000 100644 --- a/config/syslog-ng.conf.d/bind-dns.conf +++ b/config/syslog-ng.conf.d/bind-dns.conf @@ -38,9 +38,18 @@ parser p_docker_header { ); }; +parser p_client_ip_port { + csv-parser( + template("${bind9.client.ip_port}") + flags(strip-whitespace) + delimiters("#") + columns("bind9.client.ip", "bind9.client.port") + ); +}; + parser p_bind_client_ip_geoip2_city { geoip2( - "${kv.SRC}", + "${bind9.client.ip}", prefix( "geoip2.source." ) database( "/config/GeoIP/GeoLite2-City.mmdb" ) ); @@ -66,6 +75,8 @@ log { parser(p_bind_message); rewrite(r_docker_header); parser(p_docker_header); + parser(p_client_ip_port); + parser(p_bind_client_ip_geoip2_city); destination(d_bind_logs); flags(final); }; diff --git a/docker-compose.yml b/docker-compose.yml index 3486e84..077ea8d 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.10 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240619.1.11 container_name: syslog-ng restart: unless-stopped networks: