Skip to content
This repository has been archived by the owner on Apr 19, 2021. It is now read-only.

Parser additions #15

Merged
merged 25 commits into from Jul 29, 2016
Merged

Conversation

theflakes
Copy link
Contributor

Added a couple Cisco deny log parsers.
Added MS DHCP parsers.
Added a new ELSA class for HIPS/HIDS logs.

I tried to add a new IIS log parser but that is causing merge problems. Will revisit.

Added two parsers for a couple other Cisco ASA deny logs I have seen a lot of lately.
Used to parse AV, HIPS, Anti-Malware, and other host based intrusion protection logs into.
Parse AV, Anti-Malware, HIPS, and logs from other host intrusion prevention tools into.
Symantec process block parser.
add another parser to handle a slight variation on the first Symantec parser
@theflakes
Copy link
Contributor Author

Odd after rebasing I can now update the iis parser without it complaining. I left the iis parser formatting alone so its a little messy. Still have a lot to learn...

@dougburks
Copy link
Contributor

Thanks, Brian!

@theflakes
Copy link
Contributor Author

Added SQL updates to create new CITRIX_NETSCALER class and parsers for Citrix NetScaler syslog sent to OSSEC via syslog. Used "type" field to subdivide the NetScaler syslog message types into their subgroups.

@dougburks dougburks merged commit 45bf7d0 into Security-Onion-Solutions:master Jul 29, 2016
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants