mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-09-03 00:36:21 +00:00
clean up log sources
This commit is contained in:
parent
106193fac5
commit
5754c79086
1 changed files with 0 additions and 16 deletions
16
docker/elk/logstash/dist/logstash.conf
vendored
16
docker/elk/logstash/dist/logstash.conf
vendored
|
@ -50,12 +50,6 @@ input {
|
||||||
type => "ElasticPot"
|
type => "ElasticPot"
|
||||||
}
|
}
|
||||||
|
|
||||||
# eMobility
|
|
||||||
file {
|
|
||||||
path => ["/data/emobility/log/centralsystemEWS.log"]
|
|
||||||
type => "eMobility"
|
|
||||||
}
|
|
||||||
|
|
||||||
# Glastopf
|
# Glastopf
|
||||||
file {
|
file {
|
||||||
path => ["/data/glastopf/log/glastopf.log"]
|
path => ["/data/glastopf/log/glastopf.log"]
|
||||||
|
@ -231,16 +225,6 @@ filter {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
# eMobility
|
|
||||||
if [type] == "eMobility" {
|
|
||||||
grok {
|
|
||||||
match => [ "message", "\A%{IP:src_ip}\.%{POSINT:src_port:integer}\|%{IP:dest_ip}\.%{POSINT:dest_port:integer}:%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424SD}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{SYSLOG5424PRINTASCII}%{SPACE}%{URIPROTO:http_method}\|%{URIPATH:http_uri}\|%{TIMESTAMP_ISO8601:timestamp}" ]
|
|
||||||
}
|
|
||||||
date {
|
|
||||||
match => [ "timestamp", "ISO8601" ]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
# Glastopf
|
# Glastopf
|
||||||
if [type] == "Glastopf" {
|
if [type] == "Glastopf" {
|
||||||
grok {
|
grok {
|
||||||
|
|
Loading…
Reference in a new issue