Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch 'master' into dev-download-shared-files
- Loading branch information
Showing
141 changed files
with
3,055 additions
and
1,283 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,73 @@ | ||
<!-- | ||
- MariaDB decoders | ||
- Created by Wazuh, Inc. <support@wazuh.com>. | ||
- This program is a free software; you can redistribute it and/or modify it under the terms of GPLv2. | ||
--> | ||
|
||
|
||
<!-- | ||
- More log examples would be appreciated | ||
--> | ||
|
||
<!-- | ||
May 24 11:51:30 mysql09a mysql-server_auditing: mysql09a.local,ahc_shwb01_t,ahc-web29d.local,849705,0,DISCONNECT,ahc_shwb01_t,,0 | ||
20170817 16:04:33,ip-172-30-0-38,root,localhost,29,913,READ,company,employees_salaries, | ||
2017-09-25 10:25:36 139864032768576 [Note] InnoDB: Highest supported file format is Barracuda. | ||
--> | ||
|
||
<decoder name="mariadb-syslog"> | ||
<program_name>mysql</program_name> | ||
</decoder> | ||
|
||
<!-- | ||
May 24 11:51:30 mysql09a mysql-server_auditing: mysql09a.local,ahc_shwb01_t,ahc-web29d.local,849705,0,DISCONNECT,ahc_shwb01_t,,0 | ||
--> | ||
<decoder name="mariadb-syslog-fields"> | ||
<parent>mariadb-syslog</parent> | ||
<regex> (\.*),(\.*),(\.*),(\.*),(\.*),(\.*),(\.*),(\.*),(\.*)</regex> | ||
<order>mariadb.info,mariadb.username,mariadb.host,mariadb.connectionid,mariadb.queryid,mariadb.operation,mariadb.database,mariadb.object,mariadb.retcode</order> | ||
</decoder> | ||
|
||
<!-- | ||
MariaDB Table events | ||
20170817 16:04:33,ip-172-30-0-38,root,localhost,29,913,READ,company,employees_salaries, | ||
--> | ||
|
||
<decoder name="mariadb-syslog"> | ||
<prematch>^\d+\s+\S+,ip-</prematch> | ||
</decoder> | ||
|
||
<decoder name="mariadb-syslog-fields-2"> | ||
<parent>mariadb-syslog</parent> | ||
<regex>ip-(\.*),(\.*),(\.*),\.*,\.*,(\.*),(\.*)</regex> | ||
<order>mariadb.ip,mariadb.username,mariadb.host,mariadb.action,mariadb.resource</order> | ||
</decoder> | ||
|
||
|
||
<!-- | ||
MariaDB log_error | ||
2017-09-25 9:40:07 140509614809664 [Note] InnoDB: Mutexes and rw_locks use GCC atomic builtins | ||
2017-10-02 0:21:24 139861115417152 [Warning] InnoDB: New log files created, LSN=145690444812 | ||
2017-09-25 10:12:05 139667224206080 [ERROR] mysqld: Table './example' is marked as crashed and should be repaired | ||
2017-09-25 10:25:05 139665896770304 [Note] Event Scheduler: Purging the queue. 0 events | ||
--> | ||
<decoder name="mariadb-syslog"> | ||
<prematch>^\S+\s+\S+\s+\d+\s+[\w+]\s+InnoDB:</prematch> | ||
</decoder> | ||
|
||
<decoder name="mariadb-syslog"> | ||
<prematch>^\S+\s+\S+\s+\d+\s+[\w+]\s+mysqld:</prematch> | ||
</decoder> | ||
|
||
<decoder name="mariadb-syslog"> | ||
<prematch>^\S+\s+\S+\s+\d+\s+[\w+]\s+Event Scheduler:</prematch> | ||
</decoder> | ||
|
||
<decoder name="mariadb-errors"> | ||
<parent>mariadb-syslog</parent> | ||
<regex>([\w+])\s+(\.*)$</regex> | ||
<order>mariadb.type,mariadb.log</order> | ||
</decoder> | ||
|
||
|
||
|
Oops, something went wrong.