Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- =============/etc/logstash/conf.d/ufw.conf=======================
- input {
- file {
- type => "ufw"
- start_position => "beginning"
- path => "/var/log/ufw.log"
- }
- }
- filter {
- if [type] == "ufw" {
- grok {
- match => ["message", "%{SYSLOGTIMESTAMP: timestamp}\s%{WORD:host}\skernel:\s\[%{NUMBER:kernel_timestamp}\]\s\[UFW BLOCK\]\sIN=%{WORD:adapter}\sOUT=\sMAC=%{MAC:dst_mac}:%{MAC:src_mac}:(?<ethertype>\d+:\d+)\sSRC=%{IP:src_ip}\sDST=%{IP:dst_ip}\s%{GREEDYDATA:packet_details}"]
- }
- geoip {
- source => "src_ip"
- }
- }
- }
- ============= Elasticsearch Template ==========================
- curl -XPUT 'localhost:9200/_template/template_ufw?pretty' -H 'Content-Type: application/json' -d'
- {
- "index_patterns": ["ufw*"],
- "settings": {
- "refresh_interval" : "10s",
- "number_of_shards" : "1"
- },
- "mappings" : {
- "doc" : {
- "properties" : {
- "timestamp" : {
- "type" : "date"
- },
- "kernel_timestamp" : {
- "type" : "number"
- },
- "@version" : {
- "type" : "keyword"
- },
- "host" : {
- "type" : "keyword"
- },
- "adapter" : {
- "type" : "keyword"
- },
- "src_ip" : {
- "type" : "ip"
- },
- "src_mac" : {
- "type" : "keyword"
- },
- "dst_mac" : {
- "type" : "keyword"
- },
- "ethertype" : {
- "type" : "keyword"
- },
- "dst_ip" : {
- "type" : "ip"
- },
- "geoip" : {
- "dynamic" : "true",
- "properties" : {
- "city_name" : {
- "type" : "keyword"
- },
- "continent_code" : {
- "type" : "keyword"
- },
- "country_code2" : {
- "type" : "keyword"
- },
- "country_code3" : {
- "type" : "keyword"
- },
- "country_name" : {
- "type" : "keyword"
- },
- "dma_code" : {
- "type" : "long"
- },
- "ip" : {
- "type" : "ip"
- },
- "latitude" : {
- "type" : "half_float"
- },
- "location" : {
- "type" : "geo_point"
- },
- "longitude" : {
- "type" : "half_float"
- },
- "postal_code" : {
- "type" : "keyword"
- },
- "region_code" : {
- "type" : "keyword"
- },
- "region_name" : {
- "type" : "keyword"
- },
- "timezone" : {
- "type" : "keyword"
- }
- }
- },
- "packet_details" : {
- "type" : "text"
- }
- }
- }
- }
- }
- }'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement