Please, is there any body who has an example of filter grok or fils .conf that can be use with logs that came from firwalls, I want him to separate all the fields.
Can you more elaborate what is the format of your logs its CSV or JSON and so on. ?
Thanks & Regards,
If you could post into a CSV format will be great onto my files they are seppareted with Spaces
There format is : syslog (text files)
Thank you for your answer.
thanks for your soon reply @asalma , but I was guessing if you could send me some real example like in this format of log how would you configure your CSV
Pablo msg_id="3000-3001" 07-05-2018 192.168.3.105
Syslog can contain a lot of different formats, so you will need to be more specific and show examples. See this post for some additional details.
May 3 11:39:58 fwghcadmin : %ASA-6-302015: Built outbound UDP connection 2356737924 for int-850-IntercoEXTCorporate:x.x.x.x/161 (x.x.x.x/161) to int-148-GHCTechnicalInfra:x.x.x.x/34300 (x.x.x.x/34300)
Or this :
May 3 13:16:23 frkeofwdmz01m.fr.ghc.local 1,2018/05/03 13:16:22,001801039811,TRAFFIC,end,0,2018/05/03 13:16:22,x.x.x.x,x.x.x.x,0.0.0.0,0.0.0.0,CETSI-114,,,ping,vsys1,dmz,dmz,ae1.1551,ae1.1551,frghcslnet03-4-et-Basom,2018/05/03 13:16:22,19252,2,0,0,0,0,0x100019,icmp,allow,280,140,140,4,2018/05/03 13:16:11,0,any,0,22749029075,0x0,x.x.x.x-10.255.255.255,x.x.x.x-10.255.255.255,0,2,2,aged-out,0,0,0,0,,frkeofwdmz01m,from-policy
Please I need a filter that can do this :
"timestamp" => May 3 11:39:58
"host" => fwghcadmin
"ciscotag" => Type d'équipement : %ASA
Critisité : 6 ID :302015
"connection_id" => 2356737924
"operation" => Built
"protoco" => UDP
"src_interface" => int-850-IntercoEXTCorporate1
"src_ip" => x.x.x.x
"src_port" => 161
"src_mapped_ip" => x.x.x.x
"src_mapped_port" => 161
"dst_interface" => int-148-GHCTechnicalInfra
"dst_ip" => x.x.x.x
"dst_port" => 34300
"dst_mapped_ip" => x.x.x.x
"dst_mapped_port" => 34300
@asalma follow this guide is so usefull:
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.