diff --git a/decoder.xml b/decoder.xml index 6757cd0..81a4308 100644 --- a/decoder.xml +++ b/decoder.xml @@ -27,13 +27,13 @@ cgfw-firewall-activity srcIP=([\d\.]+) - SourceIP + srcip cgfw-firewall-activity srcPort=([\d\s]+) - SourcePort + srcport @@ -45,13 +45,13 @@ cgfw-firewall-activity dstIP=([\d\.]+) - DestinationIP + dstip cgfw-firewall-activity dstPort=([\w\s]+) - DestinationPort + dstport