-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathlocal_decoder.xml
121 lines (100 loc) · 2.66 KB
/
local_decoder.xml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
<!-- /var/ossec/etc/decoders/local_decoder.xml -->
<!-- KSC Custom Decoders -->
<decoder name="Kaspersky">
<prematch>event@23668</prematch>
</decoder>
<!-- или доменное имя сервера KSC, идущее в логах перед |11.0.0.0 - например: KES для лога KES|11.0.0.0
<decoder name="Kaspersky">
<prematch>KES</prematch>
</decoder>
-->
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>hdn="(\S+)"</regex>
<order>host</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>hip="(\d+.\d+.\d+.\d+)"</regex>
<order>dstip</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>tdn="(\.*)"</regex>
<order>KES.module</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>etdn="(\.*)"</regex>
<order>KES.module.action</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>gn="(\.*)"</regex>
<order>KES.group</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>kscfqdn="(\.*)"</regex>
<order>KES.server</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>event@(\d+)</regex>
<order>KES.event</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>https://(\.*)"|http://(\.*)"</regex>
<order>url</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p1="(\.*)"</regex>
<order>KES.p1</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p2="(\.*)"</regex>
<order>KES.p2</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p3="(\.*)"</regex>
<order>KES.p3</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p4="(\.*)"</regex>
<order>KES.p4</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p5="(\.*)"</regex>
<order>KES.p5</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p6="(\.*)"</regex>
<order>KES.p6</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p7="(\.*)"</regex>
<order>KES.p7</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>p8="(\.*)"</regex>
<order>KES.p8</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>\\\\(\.*)"</regex>
<order>dstuser</order>
</decoder>
<decoder name="Kaspersky-field">
<parent>Kaspersky</parent>
<regex>et="(\.*)"</regex>
<order>KES.event.code</order>
</decoder>