-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
* Updated Barracuda_Cloudgen_Firewall ParsingRules * Updated Barracuda_Cloudgen_Firewall ReleaseNotes * Updated Barracuda_Cloudgen_Firewall ReleaseNotes * Updated ParsingRules BluecatAddressManager_1_3 * Updated BluecatAddressManager ReleaseNotes * Updated BluecatAddressManager ReleaseNotes * Updated Box ParsingRules * Updated Box ReleaseNotes * Updated Box ReleaseNotes * Updated the Barracuda_Cloudgen_Firewall README * Update README.md * Updated ParsingRules Box
- Loading branch information
Showing
10 changed files
with
45 additions
and
16 deletions.
There are no files selected for viewing
3 changes: 2 additions & 1 deletion
3
...Rules/Barracuda_Cloudgen_FirewallParsingRules/Barracuda_Cloudgen_FirewallParsingRules.xif
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
|
||
#### Parsing Rules | ||
|
||
##### Barracuda Cloudgen Firewall Parsing Rules | ||
|
||
- Added a filter for the Parsing Rule to enhance its logic. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
24 changes: 16 additions & 8 deletions
24
...luecatAddressManager/ParsingRules/BluecatAddressManager_1_3/BluecatAddressManager_1_3.xif
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,15 +1,23 @@ | ||
[INGEST:vendor="bluecat", product="address_manager", target_dataset="bluecat_address_manager_raw", no_hit=keep] | ||
alter tmp_time1 = arrayindex(regextract(_raw_log,"<\d+>(\w+\s*\d+\s\d+:\d+:\d+)\s"),0), | ||
tmp_Year = format_timestamp("%Y",_insert_time) | ||
filter _raw_log ~= "<\d+>(\w+\s*\d+\s\d+:\d+:\d+)\s" | ||
| alter | ||
tmp_time1 = arrayindex(regextract(_raw_log,"<\d+>(\w+\s*\d+\s\d+:\d+:\d+)\s"),0), | ||
tmp_Year = format_timestamp("%Y",_insert_time) | ||
// Parsing time format 1 | ||
| alter tmp_time1_1 = concat(tmp_Year, " ", tmp_time1) | ||
| alter tmp_time1_1 = parse_timestamp("%Y %b %e %H:%M:%S", tmp_time1_1) | ||
| alter tmp_timeDiff = timestamp_diff(tmp_time1_1, current_time(), "DAY") | ||
| alter | ||
tmp_time1_1 = concat(tmp_Year, " ", tmp_time1) | ||
| alter | ||
tmp_time1_1 = parse_timestamp("%Y %b %e %H:%M:%S", tmp_time1_1) | ||
| alter | ||
tmp_timeDiff = timestamp_diff(tmp_time1_1, current_time(), "DAY") | ||
// Check if the date is a future date | ||
| alter tmp_Year2 = if(tmp_timeDiff > 0, to_string(subtract(to_integer(tmp_Year),1)),null) | ||
| alter | ||
tmp_Year2 = if(tmp_timeDiff > 0, to_string(subtract(to_integer(tmp_Year),1)),null) | ||
// Create timestamp minus 1 year if the timestamp is a future one | ||
| alter tmp_time1_2 = if(tmp_Year2 != null, concat(tmp_Year2, " ", tmp_time1), null) | ||
| alter tmp_time1_2 = if(tmp_time1_2 != null, parse_timestamp("%Y %b %e %H:%M:%S", tmp_time1_2), null) | ||
| alter | ||
tmp_time1_2 = if(tmp_Year2 != null, concat(tmp_Year2, " ", tmp_time1), null) | ||
| alter | ||
tmp_time1_2 = if(tmp_time1_2 != null, parse_timestamp("%Y %b %e %H:%M:%S", tmp_time1_2), null) | ||
// final result | ||
| alter _time = coalesce(tmp_time1_2, tmp_time1_1) | ||
| fields -tmp_time1, tmp_Year, tmp_Year2, tmp_timeDiff, tmp_time1_1, tmp_time1_2; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
|
||
#### Parsing Rules | ||
|
||
##### Bluecat Address Manager | ||
|
||
- Added a filter for the Parsing Rule to enhance its logic. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
5 changes: 3 additions & 2 deletions
5
Packs/Box/ParsingRules/BoxEventCollectorParsingRules/BoxEventCollectorParsingRules.xif
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,8 +1,9 @@ | ||
[INGEST:vendor="box", product="box", target_dataset="box_box_raw", no_hit=keep] | ||
alter | ||
filter created_at ~= "\d{4}-\d{2}-\d{2}T" | ||
| alter | ||
tmp_create_at_string = to_string(created_at) | ||
| alter | ||
tmp_parse_created = if(created_at ~= "\d{4}-\d{2}-\d{2}T", parse_timestamp("%Y-%m-%dT%H:%M:%S%Ez", tmp_create_at_string), _insert_time) | ||
tmp_parse_created = parse_timestamp("%Y-%m-%dT%H:%M:%S%Ez", tmp_create_at_string) | ||
| alter | ||
_time = tmp_parse_created | ||
| fields -tmp_create_at_string, tmp_parse_created; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
|
||
#### Parsing Rules | ||
|
||
##### BoxEventCollector Parsing Rule | ||
|
||
- Added a filter for the Parsing Rule to enhance its logic. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters