diff --git a/11-pfsense.conf b/11-pfsense.conf index 9f2ae40b3a10e46f70d12230d98983c764ba7ac1..adf1895bc4a5243705457f2e1f21a0873095d63c 100644 --- a/11-pfsense.conf +++ b/11-pfsense.conf @@ -45,8 +45,8 @@ if [prog] =~ /^filterlog$/ { grok { patterns_dir => "/etc/logstash/conf.d/patterns" match => [ "message", "%{PFSENSE_LOG_DATA}%{PFSENSE_IP_SPECIFIC_DATA}%{PFSENSE_IP_DATA}%{PFSENSE_PROTOCOL_DATA}", - "message", "%{PFSENSE_LOG_DATA}%{PFSENSE_IPv4_SPECIFIC_DATA}%{PFSENSE_IP_DATA}%{PFSENSE_PROTOCOL_DATA}", - "message", "%{PFSENSE_LOG_DATA}%{PFSENSE_IPv6_SPECIFIC_DATA}%{PFSENSE_IP_DATA}%{PFSENSE_PROTOCOL_DATA}"] + "message", "%{PFSENSE_IPv4_SPECIFIC_DATA}%{PFSENSE_IP_DATA}%{PFSENSE_PROTOCOL_DATA}", + "message", "%{PFSENSE_IPv6_SPECIFIC_DATA}%{PFSENSE_IP_DATA}%{PFSENSE_PROTOCOL_DATA_IPv6}"] } mutate { lowercase => [ 'proto' ]