Private GIT

Skip to content
Snippets Groups Projects
Unverified Commit b40847fd authored by Andrew's avatar Andrew Committed by GitHub
Browse files

Update 11-pf.conf

Fix for OPNsense v19.7+
parent 8fdba557
No related branches found
No related tags found
No related merge requests found
...@@ -2,7 +2,10 @@ filter { ...@@ -2,7 +2,10 @@ filter {
if "pf" in [tags] { if "pf" in [tags] {
grok { grok {
add_tag => [ "firewall" ] add_tag => [ "firewall" ]
match => [ "message", "<(?<evtid>.*)>(?<datetime>(?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)?|May|Jun(?:e)?|Jul(?:y)?|Aug(?:ust)?|Sep(?:tember)?|Oct(?:ober)?|Nov(?:ember)?|Dec(?:ember)?)\s+(?:(?:0[1-9])|(?:[12][0-9])|(?:3[01])|[1-9]) (?:2[0123]|[01]?[0-9]):(?:[0-5][0-9]):(?:[0-5][0-9])) (?<prog>.*?): (?<msg>.*)" ] #PFsense
#match => [ "message", "<(?<evtid>.*)>(?<datetime>(?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)?|May|Jun(?:e)?|Jul(?:y)?|Aug(?:ust)?|Sep(?:tember)?|Oct(?:ober)?|Nov(?:ember)?|Dec(?:ember)?)\s+(?:(?:0[1-9])|(?:[12][0-9])|(?:3[01])|[1-9]) (?:2[0123]|[01]?[0-9]):(?:[0-5][0-9]):(?:[0-5][0-9])) (?<prog>.*?): (?<msg>.*)" ]
#OPNsense
match => [ "message", "<(?<evtid>.*)>(?<datetime>(?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)?|May|Jun(?:e)?|Jul(?:y)?|Aug(?:ust)?|Sep(?:tember)?|Oct(?:ober)?|Nov(?:ember)?|Dec(?:ember)?)\s+(?:(?:0[1-9])|(?:[12][0-9])|(?:3[01])|[1-9]) (?:2[0123]|[01]?[0-9]):(?:[0-5][0-9]):(?:[0-5][0-9])) (?<firewall>.*?) (?<prog>.*?): (?<msg>.*)" ]
} }
mutate { mutate {
gsub => ["datetime"," "," "] gsub => ["datetime"," "," "]
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment