Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add a field "id" to the json log. #1090

Merged
merged 2 commits into from Mar 15, 2017
Merged

Add a field "id" to the json log. #1090

merged 2 commits into from Mar 15, 2017

Conversation

ddpbsd
Copy link
Member

@ddpbsd ddpbsd commented Mar 10, 2017

This should match up to the number following Alert in the regular alert log. I'm not sure "id" is descriptive enough, but I wanted to keep it short. Also, I'm not sure it's in the right spot of the log message. Maybe that doesn't even matter.

{"rule":{"level":3,"comment":"Login session closed.","sidid":5502,"group":"pam,syslog,"},"id":"1489183089.253799","decoder":"pam","location":"/var/log/syslog-ng/messages","full_log":"Mar  8 20:13:39 ubnt sudo: pam_unix(sudo:session): session closed for user root","TimeStamp":"Fri Mar 10 16:58:09 2017\n","hostname":"ubnt","program_name":"sudo"}
** Alert 1489183089.253799: - pam,syslog,
2017 Mar 10 16:58:09 ubnt->/var/log/syslog-ng/messages
Rule: 5502 (level 3) -> 'Login session closed.'
Mar  8 20:13:39 ubnt sudo: pam_unix(sudo:session): session closed for user root

This change is Reviewable

I'm not sure this is the best place for it yet, but it seems to work.
Copy link
Member

@jrossi jrossi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good to me.

@ddpbsd ddpbsd merged commit 1ec34de into ossec:master Mar 15, 2017
@ddpbsd ddpbsd deleted the alertid branch November 26, 2018 14:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants