From 9099c7452986a0d585e44fd33302e120cc3f09d2 Mon Sep 17 00:00:00 2001 From: Daniel Melgarejo Date: Tue, 12 May 2020 09:54:17 +0200 Subject: [PATCH] Added decoder for UFW logs --- decoders/0140-kernel_decoders.xml | 37 ++++++++++++++++++++++++++++++- 1 file changed, 36 insertions(+), 1 deletion(-) diff --git a/decoders/0140-kernel_decoders.xml b/decoders/0140-kernel_decoders.xml index a61a4c2d0..3d2095273 100644 --- a/decoders/0140-kernel_decoders.xml +++ b/decoders/0140-kernel_decoders.xml @@ -97,7 +97,7 @@ Example: kernel firewall - ^[\d+.\d+] \S+\.*IN= + ^[\d+.\d+] \S+\(\.*IN= ^[\d+.\d+] (\S*)\( action @@ -123,6 +123,41 @@ Example: srcport,dstport + + + + kernel + firewall + ^[\d+.\d+] [UFW \S+] IN= + ^[\d+.\d+] [UFW (\S+)] + action + + + + kernel + firewall + SRC=(\S+) DST=(\S+) + srcip,dstip + + + + kernel + firewall + PROTO=(\w+) + protocol + + + + kernel + firewall + SPT=(\d+) DPT=(\d+) + srcport,dstport + +