Skip to content

Commit b27ebe6

Browse files
committed
sample output
1 parent 6d53789 commit b27ebe6

1 file changed

Lines changed: 110 additions & 0 deletions

File tree

README.md

Lines changed: 110 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,3 +49,113 @@ If logstash has been installed from the logstash repository (http://www.logstash
4949

5050
`tail -f /var/log/logstash/logstash.stdout`
5151

52+
53+
### Sample output event
54+
```
55+
{
56+
  "@timestamp": "2013-09-17T09:46:16.088Z",
57+
  "@version": "1",
58+
  "host": "razzle2",
59+
  "path": "/Users/bof/who2/zip4n/logstash/modseclogs/proxy9/modsec_audit.log.1",
60+
  "tags": [
61+
    "multiline"
62+
  ],
63+
  "rawSectionA": "[17/Sep/2013:05:46:16 --0400] MSZkdwoB9ogAAHlNTXUAAAAD 192.168.0.9 65183 192.168.0.136 80",
64+
  "rawSectionB": "POST /xml/rpc/soapservice-v2 HTTP/1.1\nContent-Type: application/xml\nspecialcookie: tb034=\nCache-Control: no-cache\nPragma: no-cache\nUser-Agent: Java/1.5.0_15\nHost: xmlserver.intstage442.org\nAccept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2\nConnection: keep-alive\nContent-Length: 93\nIncoming-Protocol: HTTPS\nab0044: 0\nX-Forwarded-For: 192.168.1.232",
65+
  "rawSectionC": {
66+
    "id": 2,
67+
    "method": "report",
68+
    "stuff": [
69+
      "kborg2@special292.org",
70+
      "X22322mkf3"
71+
    ],
72+
    "xmlrpm": "0.1a"
73+
  },
74+
  "rawSectionF": "HTTP/1.1 200 OK\nX-SESSTID: 009nUn4493\nContent-Type: application/xml;charset=UTF-8\nContent-Length: 76\nConnection: close",
75+
  "rawSectionH": "Message: Warning. Match of \"rx (?:^(?:application\\\\/x-www-form-urlencoded(?:;(?:\\\\s?charset\\\\s?=\\\\s?[\\\\w\\\\d\\\\-]{1,18})?)??$|multipart/form-data;)|text/xml)\" against \"REQUEST_HEADERS:Content-Type\" required. [file \"/opt/niner/modsec2/pp7.conf\"] [line \"69\"] [id \"960010\"] [msg \"Request content type is not allowed by policy\"] [severity \"WARNING\"] [tag \"POLICY/ENCODING_NOT_ALLOWED\"]\nApache-Handler: party-server-time2\nStopwatch: 1379411176088695 48158 (1771* 3714 -)\nProducer: ModSecurity for Apache/2.7 (http://www.modsecurity.org/); core ruleset/1.9.2.\nServer: Whoisthat/v1 (Osprey)",
76+
  "modsec_timestamp": "17/Sep/2013:05:46:16 --0400",
77+
  "uniqueId": "MSZkdwoB9ogAAHlNTXUAAAAD",
78+
  "sourceIp": "192.168.0.9",
79+
  "sourcePort": "65183",
80+
  "destIp": "192.168.0.136",
81+
  "destPort": "80",
82+
  "httpMethod": "POST",
83+
  "requestedUri": "/xml/rpc/soapservice-v2",
84+
  "incomingProtocol": "HTTP/1.1",
85+
  "requestBody": {
86+
    "id": 2,
87+
    "method": "report",
88+
    "stuff": [
89+
      "kborg2@special292.org",
90+
      "X22322mkf3"
91+
    ],
92+
    "xmlrpm": "0.1a"
93+
  },
94+
  "serverProtocol": "HTTP/1.1",
95+
  "responseStatus": "200 OK",
96+
  "requestHeaders": {
97+
    "Content-Type": "application/xml",
98+
    "specialcookie": "8jj220021kl==j2899IuU",
99+
    "Cache-Control": "no-cache",
100+
    "Pragma": "no-cache",
101+
    "User-Agent": "Java/1.5.1_15",
102+
    "Host": "xmlserver.intstage442.org",
103+
    "Accept": "text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2",
104+
    "Connection": "keep-alive",
105+
    "Content-Length": "93",
106+
    "Incoming-Protocol": "HTTPS",
107+
    "ab0044": "0",
108+
    "X-Forwarded-For": "192.168.1.232"
109+
  },
110+
  "responseHeaders": {
111+
    "X-SESSTID": "009nUn4493",
112+
    "Content-Type": "application/xml;charset=UTF-8",
113+
    "Content-Length": "76",
114+
    "Connection": "close"
115+
  },
116+
  "auditLogTrailer": {
117+
    "Apache-Handler": "party-server-time2",
118+
    "Stopwatch": "1379411176088695 48158 (1771* 3714 -)",
119+
    "Producer": "ModSecurity for Apache/2.7 (http://www.modsecurity.org/); core ruleset/1.9.2.",
120+
    "Server": "Whoisthat/v1 (Osprey)",
121+
    "messages": [
122+
      {
123+
        "info": "Warning. Match of \"rx (?:^(?:application\\\\/x-www-form-urlencoded(?:;(?:\\\\s?charset\\\\s?=\\\\s?[\\\\w\\\\d\\\\-]{1,18})?)??$|multipart/form-data;)|text/xml)\" against \"REQUEST_HEADERS:Content-Type\" required.",
124+
        "file": "/opt/niner/modsec2/pp7.conf",
125+
        "line": "69",
126+
        "id": "960010",
127+
        "msg": "Request content type is not allowed by policy",
128+
        "severity": "WARNING",
129+
        "tag": "POLICY/ENCODING_NOT_ALLOWED"
130+
      }
131+
    ]
132+
  },
133+
  "event_date_microseconds": 1.37941116E15,
134+
  "event_date_milliseconds": 1.37941117E12,
135+
  "event_date_seconds": 1.3794112E9,
136+
  "event_timestamp": "2013-09-17T09:46:16.088Z",
137+
  "XForwardedFor-GEOIP": {
138+
    "ip": "192.168.1.122",
139+
    "country_code2": "XZ",
140+
    "country_code3": "BRZ",
141+
    "country_name": "Brazil",
142+
    "continent_code": "SA",
143+
    "region_name": "12",
144+
    "city_name": "Vesper",
145+
    "postal_code": "",
146+
    "timezone": "Brazil/Continental",
147+
    "real_region_name": "Region Metropolitana"
148+
  },
149+
  "matchedRules": [
150+
    "SecRule \"REQUEST_METHOD\" \"@rx ^POST$\" \"phase:2,status:400,t:lowercase,t:replaceNulls,t:compressWhitespace,chain,t:none,deny,log,auditlog,msg:'POST request must have a Content-Length header',id:960022,tag:PROTOCOL_VIOLATION/EVASION,severity:4\"",
151+
    "SecRule \"REQUEST_FILENAME|ARGS|ARGS_NAMES|REQUEST_HEADERS|XML:/*|!REQUEST_HEADERS:Referer\" \"@pm jscript onsubmit onchange onkeyup activexobject vbscript: <![cdata[ http: settimeout onabort shell: .innerhtml onmousedown onkeypress asfunction: onclick .fromcharcode background-image: .cookie onunload createtextrange onload <input\" \"phase:2,status:406,t:lowercase,t:replaceNulls,t:compressWhitespace,t:none,t:urlDecodeUni,t:htmlEntityDecode,t:compressWhiteSpace,t:lowercase,nolog,skip:1\"",
152+
    "SecAction \"phase:2,status:406,t:lowercase,t:replaceNulls,t:compressWhitespace,nolog,skipAfter:950003\"",
153+
    "SecRule \"REQUEST_HEADERS|XML:/*|!REQUEST_HEADERS:'/^(Cookie|Referer|X-OS-Prefs)$/'|REQUEST_COOKIES|REQUEST_COOKIES_NAMES\" \"@pm gcc g++\" \"phase:2,status:406,t:lowercase,t:replaceNulls,t:compressWhitespace,t:none,t:urlDecodeUni,t:htmlEntityDecode,t:lowercase,nolog,skip:1\""
154+
  ],
155+
  "secRuleIds": [
156+
    "960022",
157+
    "960050"
158+
  ]
159+
}
160+
```
161+

0 commit comments

Comments
 (0)