From f33a5e63e7ea0a939ac67c009006e820292b30bb Mon Sep 17 00:00:00 2001 From: Kameron Kenny <1267885+kkenny@users.noreply.github.com> Date: Mon, 17 Jun 2024 12:52:02 -0400 Subject: [PATCH] parse kv pairs for suricata --- Dockerfile | 2 +- config/syslog-ng.conf | 1 + docker-compose.yml | 2 +- 3 files changed, 3 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 43dc5c3..fcd7197 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,6 +1,6 @@ FROM lscr.io/linuxserver/syslog-ng:latest -LABEL version="20240617.1.1" +LABEL version="20240617.1.2" LABEL description="syslog-ng" RUN mkdir -p /config diff --git a/config/syslog-ng.conf b/config/syslog-ng.conf index e37690f..3c495aa 100644 --- a/config/syslog-ng.conf +++ b/config/syslog-ng.conf @@ -175,6 +175,7 @@ log { source(s_network_udp); filter(f_unifi_suricata); destination(d_unifi_suricata); + parser(p_kv); flags(final); }; diff --git a/docker-compose.yml b/docker-compose.yml index a678630..7e02963 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -10,7 +10,7 @@ services: syslog-ng: build: dockerfile: Dockerfile - image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240617.1.1 + image: docker-registry1.in.thelinuxpro.net:5000/tlp/syslog-ng:240617.1.2 container_name: syslog-ng environment: - PUID=0