Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- {
- "extractors": [
- {
- "title": "message",
- "extractor_type": "regex",
- "converters": [],
- "order": 3,
- "cursor_strategy": "copy",
- "source_field": "message",
- "target_field": "message",
- "extractor_config": {
- "regex_value": "(?:.*)(?:%.*: )(.*)"
- },
- "condition_type": "none",
- "condition_value": ""
- },
- {
- "title": "mnemonic",
- "extractor_type": "regex",
- "converters": [],
- "order": 2,
- "cursor_strategy": "copy",
- "source_field": "message",
- "target_field": "mnemonic",
- "extractor_config": {
- "regex_value": "(?:.*%......)(.*[0-9])(?:: .*)"
- },
- "condition_type": "none",
- "condition_value": ""
- },
- {
- "title": "Deny_Public_Source_IP",
- "extractor_type": "regex",
- "converters": [],
- "order": 0,
- "cursor_strategy": "copy",
- "source_field": "message",
- "target_field": "Deny_Public_Source_IP",
- "extractor_config": {
- "regex_value": "Deny \\w{1,4} \\w{1,4} \\w{1,4}:((\\d+)(?<!10)\\.(\\d+)(?<!192\\.168)(?<!172\\.(1[6-9]|2\\d|3[0-1]))\\.(\\d+)\\.(\\d+))"
- },
- "condition_type": "none",
- "condition_value": ""
- },
- {
- "title": "severity level",
- "extractor_type": "regex",
- "converters": [],
- "order": 1,
- "cursor_strategy": "copy",
- "source_field": "message",
- "target_field": "severity",
- "extractor_config": {
- "regex_value": "(?:.*%ASA-)(.)(?:.*)"
- },
- "condition_type": "none",
- "condition_value": ""
- },
- {
- "title": "source_ip",
- "extractor_type": "regex",
- "converters": [],
- "order": 0,
- "cursor_strategy": "copy",
- "source_field": "message",
- "target_field": "source_ip",
- "extractor_config": {
- "regex_value": "for \\w{1,20}\\:(\\d{1,3}.\\d{1,3}.\\d{1,3}.\\d{1,3})"
- },
- "condition_type": "none",
- "condition_value": ""
- },
- {
- "title": "destination_ip",
- "extractor_type": "regex",
- "converters": [],
- "order": 0,
- "cursor_strategy": "copy",
- "source_field": "message",
- "target_field": "destination_ip",
- "extractor_config": {
- "regex_value": "to \\w{1,20}\\:(\\d{1,3}.\\d{1,3}.\\d{1,3}.\\d{1,3})"
- },
- "condition_type": "none",
- "condition_value": ""
- }
- ],
- "version": "3.0.0-rc.1"
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement