Change to srcip so the geolocation works
This commit is contained in:
parent
c8b795d9ea
commit
731eeed1c2
@ -27,13 +27,13 @@
|
|||||||
<decoder name="cgfw-firewall-activity-fields">
|
<decoder name="cgfw-firewall-activity-fields">
|
||||||
<parent>cgfw-firewall-activity</parent>
|
<parent>cgfw-firewall-activity</parent>
|
||||||
<regex type="pcre2">srcIP=([\d\.]+)</regex>
|
<regex type="pcre2">srcIP=([\d\.]+)</regex>
|
||||||
<order>SourceIP</order>
|
<order>srcip</order>
|
||||||
</decoder>
|
</decoder>
|
||||||
|
|
||||||
<decoder name="cgfw-firewall-activity-fields">
|
<decoder name="cgfw-firewall-activity-fields">
|
||||||
<parent>cgfw-firewall-activity</parent>
|
<parent>cgfw-firewall-activity</parent>
|
||||||
<regex type="pcre2">srcPort=([\d\s]+)</regex>
|
<regex type="pcre2">srcPort=([\d\s]+)</regex>
|
||||||
<order>SourcePort</order>
|
<order>srcport</order>
|
||||||
</decoder>
|
</decoder>
|
||||||
|
|
||||||
<decoder name="cgfw-firewall-activity-fields">
|
<decoder name="cgfw-firewall-activity-fields">
|
||||||
@ -45,13 +45,13 @@
|
|||||||
<decoder name="cgfw-firewall-activity-fields">
|
<decoder name="cgfw-firewall-activity-fields">
|
||||||
<parent>cgfw-firewall-activity</parent>
|
<parent>cgfw-firewall-activity</parent>
|
||||||
<regex type="pcre2">dstIP=([\d\.]+)</regex>
|
<regex type="pcre2">dstIP=([\d\.]+)</regex>
|
||||||
<order>DestinationIP</order>
|
<order>dstip</order>
|
||||||
</decoder>
|
</decoder>
|
||||||
|
|
||||||
<decoder name="cgfw-firewall-activity-fields">
|
<decoder name="cgfw-firewall-activity-fields">
|
||||||
<parent>cgfw-firewall-activity</parent>
|
<parent>cgfw-firewall-activity</parent>
|
||||||
<regex type="pcre2">dstPort=([\w\s]+)</regex>
|
<regex type="pcre2">dstPort=([\w\s]+)</regex>
|
||||||
<order>DestinationPort</order>
|
<order>dstport</order>
|
||||||
</decoder>
|
</decoder>
|
||||||
|
|
||||||
<decoder name="cgfw-firewall-activity-fields">
|
<decoder name="cgfw-firewall-activity-fields">
|
||||||
|
Loading…
x
Reference in New Issue
Block a user