%PDF- %PDF-
Mini Shell

Mini Shell

Direktori : /backups/router/usr/local/share/syslog-ng/include/scl/netskope/
Upload File :
Create Path :
Current File : //backups/router/usr/local/share/syslog-ng/include/scl/netskope/plugin.conf

#############################################################################
# Copyright (c) 2019 Balabit
#
# This program is free software; you can redistribute it and/or modify it
# under the terms of the GNU General Public License version 2 as published
# by the Free Software Foundation, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
#
# As an additional exemption you are allowed to compile & link against the
# OpenSSL libraries as published by the OpenSSL project. See the file
# COPYING for details.
#
#############################################################################

@requires json-plugin

# sample log
#   <134>{"count": 1, "supporting_data": {"data_values": ["x.x.x.x", "user@domain.com"], "data_type": "user"}, "organization_unit": "domain/domain/Domain Users/Enterprise Users", "severity_level": 2, "category": null, "timestamp": 1547421943, "_insertion_epoch_timestamp": 1547421943, "ccl": "unknown", "user": "user@domain.com", "audit_log_event": "Login Successful", "ur_normalized": "user@domain.com", "_id": "936289", "type": "admin_audit_logs", "appcategory": null}

# assumed to be running with flags(no-parse), e.g. the entire incoming log
# message is in $MSG
block parser netskope-parser(prefix(".netskope.")) {
    channel {
        rewrite {
            subst("^<[0-9]+>", "");
        };
        parser {
            json-parser(prefix(`prefix`));
        };
    };
};

application netskope[syslog-raw] {
    filter { message("<134>{" type(string) flags(prefix)) and message("_insertion_epoch_timestamp"); };
    parser { netskope-parser(); };
};

Zerion Mini Shell 1.0