Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- props.conf
- [ldap:open:audit]
- SHOULD_LINEMERGE = true
- BREAK_ONLY_BEFORE = ^#\s+modify\s+\d+\s+
- BREAK_ONLY_BEFORE_DATE = false
- REPORT-MultiValueAudit = loa-MultiValueAudit
- REPORT-AuditUser = loa-audituser
- transforms.conf
- [loa-MultiValueAudit]
- DELIMS="\n", ":"
- MV_ADD=true
- [loa-audituser]
- REGEX = ^# modify (\d+) (dc=[\w,=]+) (\w+=([\w\s]*),([,=\w]*))
- FORMAT = modifiedTimestamp::$1 suffix::$2 ModifiedBy::$4 ModifierBase::$5 fullModifierName::$3
- ====== EVENT TO PARSE (sourcetype=ldap:open:audit) =========
- # modify 1317923089 dc=ycp,dc=edu cn=Manager,dc=contoso,dc=com conn=-1
- dn: uid=USER,ou=People,dc=contoso,dc=com
- changetype: modify
- delete: pwdFailureTime
- -
- replace: entryCSN
- entryCSN: 20111006174450.024605Z#000000#004#000000
- -
- replace: modifiersName
- modifiersName: cn=Manager,dc=contoso,dc=com
- -
- replace: modifyTimestamp
- modifyTimestamp: 20111006174450Z
- -
- # end modify 1317923089
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement