From f277c96d59750005dab867f4027a459496125ed6 Mon Sep 17 00:00:00 2001 From: inspired Date: Wed, 5 Oct 2016 08:46:02 +0200 Subject: [PATCH] Update transforms.conf --- default/transforms.conf | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/default/transforms.conf b/default/transforms.conf index 2294943..f85b7c4 100644 --- a/default/transforms.conf +++ b/default/transforms.conf @@ -129,16 +129,16 @@ SOURCE_KEY = message_text ##################################### Specific extractions below [extract_cisco_ios-acl] -REGEX = (IPACCESSLOGP|IPACCESSLOGSP|IPACCESSLOGRP|IPACCESSLOGNP|ACCESSLOGP|ACCESSLOGSP|ACCESSLOGNP)(\s)?:(?:.+) list\s(?.+)\s(?denied|permitted)\s(?\d+|tcp|udp|igmp|ipinip|gre|eigrp|ospf|nosip|pim|sctp)\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))\(?(?\d+)?\)?(\s\((?\S+) (?\S+)\))?\s->\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))(\(?(?\d+)?\))?(, (?\S+) packet(s)?)?(\s\[(?\S+)\])? +REGEX = (IPACCESSLOGP|IPACCESSLOGSP|IPACCESSLOGRP|IPACCESSLOGNP|ACCESSLOGP|ACCESSLOGSP|ACCESSLOGNP)(\s)?:(?:.+)list\s(?.+)\s(?denied|permitted)\s(?\d+|tcp|udp|igmp|ipinip|gre|eigrp|ospf|nosip|pim|sctp)\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))\(?(?\d+)?\)?(\s\((?\S+) (?\S+)\))?\s->\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))(\(?(?\d+)?\))?(, (?\S+) packet(s)?)?(\s\[(?\S+)\])? [extract_cisco_ios-acl-2] -REGEX = IPACCESSLOGS(\s)?:(?:.+) list (?.+) (?denied|permitted) (?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::)) (?\d+) packet(s)?(\s\[(?\S+)\])? +REGEX = IPACCESSLOGS(\s)?:(?:.+)list (?.+) (?denied|permitted) (?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::)) (?\d+) packet(s)?(\s\[(?\S+)\])? [extract_cisco_ios-acl-3] -REGEX = (ACCESSLOGDP|IPACCESSLOGDP)(\s)?:(?:.+) list\s(?.+)\s(?denied|permitted)\s(?\d+|icmp|icmpv6)\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))\(?(?\d+)?\)?(\s\((?\S+) (?\S+)\))?\s->\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::)) (\(?(?\d+)\/(?\d+)?\))?(, (?\S+) packet(s)?)?(\s\[(?\S+)\])? +REGEX = (ACCESSLOGDP|IPACCESSLOGDP)(\s)?:(?:.+)list\s(?.+)\s(?denied|permitted)\s(?\d+|icmp|icmpv6)\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))\(?(?\d+)?\)?(\s\((?\S+) (?\S+)\))?\s->\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::)) (\(?(?\d+)\/(?\d+)?\))?(, (?\S+) packet(s)?)?(\s\[(?\S+)\])? [extract_cisco_ios-acl-4] -REGEX = SGACLHIT(\s)?:(?:.+) list\s(?.+)\s(?denied|permitted|Denied|Permitted)\s(?\d+|tcp|udp|igmp|ipinip|gre|eigrp|ospf|nosip|pim|sctp)\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))\(?(?\d+)?\)?(\s\((?\S+) (?\S+)\))?\s->\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))(\(?(?\d+)?\))?(, SGT\s?(?\d+) DGT\s?(?\d+))? +REGEX = SGACLHIT(\s)?:(?:.+)list\s(?.+)\s(?denied|permitted|Denied|Permitted)\s(?\d+|tcp|udp|igmp|ipinip|gre|eigrp|ospf|nosip|pim|sctp)\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))\(?(?\d+)?\)?(\s\((?\S+) (?\S+)\))?\s->\s(?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::))(\(?(?\d+)?\))?(, SGT\s?(?\d+) DGT\s?(?\d+))? [extract_cisco_ios-acl-nexus] REGEX = %ACLLOG-.+-(ACLLOG_NEW_FLOW|ACLLOG_FLOW_INTERVAL)(\s)?: Source IP: (?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::)), Destination IP: (?(?:(?:\d{1,3}\.){3}(?:\d{1,3}))|(?:(?:::)?(?:[\dA-Fa-f]{1,4}:{1,2}){1,7}(?:[\d\%A-Fa-z\.]+)?(?:::)?)|(?:::[\dA-Fa-f\.]{1,15})|(?:::)), Source Port: (?\d+), Destination Port: (?\d+), Source Interface: (?\S+)?, Protocol: "(?\S+)"\((?\d+)\), Hit-count = (?\d+)