From c8b795d9ea1a0e2cc52b69db47aa1d2afcb67a7d Mon Sep 17 00:00:00 2001 From: Joren Date: Thu, 6 Mar 2025 09:40:26 +0100 Subject: [PATCH] first commit --- decoder.xml | 164 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 164 insertions(+) create mode 100644 decoder.xml diff --git a/decoder.xml b/decoder.xml new file mode 100644 index 0000000..6757cd0 --- /dev/null +++ b/decoder.xml @@ -0,0 +1,164 @@ + + + syslog + ^.*\/box_Firewall_Activity + + + + cgfw-firewall-activity + type=([\w\s]+) + Type + + + + cgfw-firewall-activity + proto=([\w\s]+) + L4Protocol + + + + cgfw-firewall-activity + srcIF=([\w\s]+) + SourceInterface + + + + cgfw-firewall-activity + srcIP=([\d\.]+) + SourceIP + + + + cgfw-firewall-activity + srcPort=([\d\s]+) + SourcePort + + + + cgfw-firewall-activity + srcMAC=([\w\d:]+) + SourceMAC + + + + cgfw-firewall-activity + dstIP=([\d\.]+) + DestinationIP + + + + cgfw-firewall-activity + dstPort=([\w\s]+) + DestinationPort + + + + cgfw-firewall-activity + dstService=([\w\s]+) + DestinationService + + + + cgfw-firewall-activity + dstIF=([\w\s]+) + DestinationInterface + + + + cgfw-firewall-activity + rule=([\w\s\-]+) + FirewallRule + + + + cgfw-firewall-activity + info=([\w\s]+) + Info + + + + cgfw-firewall-activity + srcNAT=([\d\.]+) + SourceNAT + + + + cgfw-firewall-activity + dstNAT=([\d\.]+) + DestinationNAT + + + + cgfw-firewall-activity + duration=([\d]+) + Duration + + + + cgfw-firewall-activity + count=([\d]+) + Count + + + + cgfw-firewall-activity + receivedBytes=([\d]+) + ReceivedBytes + + + + cgfw-firewall-activity + sentBytes=([\d]+) + SentBytes + + + + cgfw-firewall-activity + receivedPackets=([\d]+) + ReceivedPackets + + + + cgfw-firewall-activity + sentPackets=([\d]+) + SentPackets + + + + cgfw-firewall-activity + user=([\w\s]+) + User + + + + cgfw-firewall-activity + protocol=([\w\s]+) + L7Protocol + + + + cgfw-firewall-activity + application=([\w\s]+) + Application + + + + cgfw-firewall-activity + target=([\w\s]+) + Target + + + + cgfw-firewall-activity + content=([\w\s]+) + Content + + + + cgfw-firewall-activity + urlcat=([\w\s]+) + URLCategory + +