-
Notifications
You must be signed in to change notification settings - Fork 20
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: allow *.xml (beside *.log) files as sample input files (#550)
- Loading branch information
1 parent
166f846
commit cf158cf
Showing
5 changed files
with
77 additions
and
8 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,52 @@ | ||
<?xml version="1.0"?> | ||
<device> | ||
<vendor>Juniper</vendor> | ||
<product>JunOS</product> | ||
<version id="16.2R1" /> | ||
<version id="17.1R1" /> | ||
<version id="17.2R1" /> | ||
<event code="" name="RT_FLOW_SESSION_CREATE" format="syslog"> | ||
<transport type="syslog" /> | ||
<source> | ||
<jira id="ADDON-25170"/> | ||
<comment>Got this event form Juniper document.</comment> | ||
</source> | ||
<raw> | ||
<![CDATA[<111> 2020-02-12T03:27:09+10:00 sample.dvc RT_FLOW: RT_FLOW_SESSION_CREATE: session created 1.1.1.1/34667->10.0.0.1/5048 0x0 junos-http 1.1.1.2/34667->10.0.0.2/5048 0x0 sample_src_rule_type sample_src_rule_name sample_dst_rule_type sample_dest_rule_n**ame 6 1660(global) SAMPLE-SERVER-ZONE DUMMY_ZONE 113256 user2(admin) gg-0/0/0.1 SNMP DUMMY_APP UNKNOWN]]> | ||
</raw> | ||
<cim> | ||
<models> | ||
<model>Network Traffic</model> | ||
</models> | ||
<cim_fields> | ||
<field name="action" value="allowed"/> | ||
<field name="dest" value="10.0.0.1"/> | ||
<field name="dest_ip" value="10.0.0.1"/> | ||
<field name="dest_port" value="5048"/> | ||
<field name="dest_zone" value="DUMMY_ZONE"/> | ||
<field name="dvc" value="sample.dvc"/> | ||
<field name="rule" value="sample_src_rule_name sample_dest_rule_n**ame 1660(global)"/> | ||
<field name="session_id" value="113256"/> | ||
<field name="src" value="1.1.1.1"/> | ||
<field name="src_ip" value="1.1.1.1"/> | ||
<field name="src_port" value="34667"/> | ||
<field name="src_zone" value="SAMPLE-SERVER-ZONE"/> | ||
<field name="src_interface" value="gg-0/0/0.1"/> | ||
<field name="user" value="user2"/> | ||
<field name="app" value="SNMP DUMMY_APP"/> | ||
<field name="transport" value="tcp"/> | ||
<field name="protocol" value="ip"/> | ||
<field name="vendor_product" value="Incorrect vendor product"/> | ||
</cim_fields> | ||
<missing_recommended_fields> | ||
<field>bytes</field> | ||
<field>bytes_in</field> | ||
<field>bytes_out</field> | ||
</missing_recommended_fields> | ||
<exceptions> | ||
<field name="vendor_product" value="Incorrect vendor product" reason="testing exceptions"/> | ||
</exceptions> | ||
</cim> | ||
<test></test> | ||
</event> | ||
</device> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters