Re: multiple pattern grok parser in 1 file

2017-10-23 Thread Simon Elliston Ball
e3d61bb6c53beb0678536e2e9b33d7996e2960/cisco-asa.conf >>>>> >>>>> [2] >>>>> https://bitbucket.org/networkintelligence/logstash-configs/raw/aae3d61bb6c53beb0678536e2e9b33d7996e2960/linux-system.conf >>>>> >>>>> [3] >

Re: multiple pattern grok parser in 1 file

2017-10-23 Thread Simon Elliston Ball
ash-configs/ >>> >>> Regards, >>> --- >>> Wasim Halani >>> http://twitter.com/washalsec >>> http://securitythoughts.wordpress.com >>> -- >>> To keep silent when you can say something wise and useful is as bad as >>

Re: multiple pattern grok parser in 1 file

2017-10-23 Thread tkg_cangkul
you can say something wise and useful is as bad as keeping on propagating foolish and unwise thoughts. -- Imam Ali (p.b.u.h.) On Mon, Oct 23, 2017 at 8:08 AM, Youzha <yuza.ras...@gmail.com <mailto:yuza.ras...@gmail.com>> wrote: Hi, is that possible to using multiple pattern gro

Re: multiple pattern grok parser in 1 file

2017-10-22 Thread tkg_cangkul
, Youzha <yuza.ras...@gmail.com <mailto:yuza.ras...@gmail.com>> wrote: Hi, is that possible to using multiple pattern grok parser ini 1 pattern file? i’m trying to parsing authlog file in /var/log/secure into metron. the problem is there are different structures of logs ins

Re: multiple pattern grok parser in 1 file

2017-10-22 Thread Wasim Halani
wrote: > Hi, is that possible to using multiple pattern grok parser ini 1 pattern > file? > i’m trying to parsing authlog file in /var/log/secure into metron. the > problem is there are different structures of logs inside /var/log/secure. > any suggest for this pls? > > > Best Regards, > >

multiple pattern grok parser in 1 file

2017-10-22 Thread Youzha
Hi, is that possible to using multiple pattern grok parser ini 1 pattern file? i’m trying to parsing authlog file in /var/log/secure into metron. the problem is there are different structures of logs inside /var/log/secure. any suggest for this pls? Best Regards,