Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- echo '2025-01-23T00:26:19+00:00 POSTFIX_SERVER postfix/smtpd[3308]: NOQUEUE: reject: RCPT from unknown[99.99.99.99]: 450 4.7.1 <discwji.sfhiwho>: Helo command reje
- cted: Host not found; from=<[email protected]> to=<[email protected]> proto=SMTP helo=<discwji.sfhiwho>' | cscli explain -f- --type syslog
- WARN Line 0/1 is missing evt.StrTime. It is most likely a mistake as it will prevent your logs to be processed in time-machine/forensic mode.
- line: 2025-01-23T00:26:19+00:00 POSTFIX_SERVER postfix/smtpd[3308]: NOQUEUE: reject: RCPT from unknown[99.99.99.99]: 450 4.7.1 <discwji.sfhiwho>: Helo command rejected: Host not found; from=<isih
- [email protected]> to=<[email protected]> proto=SMTP helo=<discwji.sfhiwho>
- ├ s00-raw
- | ├ 🔴 crowdsecurity/syslog-logs
- | └ 🔴 crowdsecurity/non-syslog
- └-------- parser failure 🔴/
- Remove the `_` in the server name
- echo '2025-01-23T00:26:19+00:00 POSTFIXSERVER postfix/smtpd[3308]: NOQUEUE: reject: RCPT from unknown[99.99.99.99]: 450 4.7.1 <discwji.sfhiwho>: Helo command rejec
- ted: Host not found; from=<[email protected]> to=<[email protected]> proto=SMTP helo=<discwji.sfhiwho>' | cscli explain -f- --type syslog
- line: 2025-01-23T00:26:19+00:00 POSTFIXSERVER postfix/smtpd[3308]: NOQUEUE: reject: RCPT from unknown[99.99.99.99]: 450 4.7.1 <discwji.sfhiwho>: Helo command rejected: Host not found; from=<isihf
- [email protected]> to=<[email protected]> proto=SMTP helo=<discwji.sfhiwho>
- ├ s00-raw
- | └ 🟢 crowdsecurity/syslog-logs (+12 ~9)
- ├ s01-parse
- | ├ 🔴 crowdsecurity/appsec-logs
- | ├ 🔴 laurencejjones/dovecot-pam
- | ├ 🔴 crowdsecurity/dovecot-logs
- | ├ 🔴 crowdsecurity/endlessh-logs
- | ├ 🔴 baudneo/gotify-logs
- | ├ 🔴 crowdsecurity/iptables-logs
- | ├ 🔴 crowdsecurity/nginx-logs
- | └ 🟢 crowdsecurity/postfix-logs (+17 ~1)
- ├ s02-enrich
- | ├ 🟢 crowdsecurity/dateparse-enrich (+2 ~2)
- | ├ 🟢 crowdsecurity/geoip-enrich (+13)
- | ├ 🔴 crowdsecurity/http-logs
- | ├ 🟢 my/whitelists (unchanged)
- | └ 🟢 crowdsecurity/whitelists (unchanged)
- ├-------- parser success 🟢/
- ├ Scenarios
- ├ 🟢 crowdsecurity/postfix-helo-rejected
- └ 🟢 crowdsecurity/postfix-spam
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement