Skip to content

Commit c0c32e0

Browse files
committed
remove pattern file
1 parent acf3024 commit c0c32e0

2 files changed

Lines changed: 2 additions & 3 deletions

File tree

2010_filter_section_a_parse.conf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,9 +6,9 @@ filter {
66
#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
77
grok {
88
match => {
9-
"rawSectionA" => "\[%{L1_TIMESTAMP:modsec_timestamp}\] %{DATA:uniqueId} %{IP:sourceIp} %{INT:sourcePort} %{IP:destIp} %{INT:destPort}"
9+
"rawSectionA" => "\[(?<modsec_timestamp>%{MONTHDAY}/%{MONTH}/%{YEAR}:%{TIME} [-\+]{1,2}%{INT})\] %{DATA:uniqueId} %{IP:sourceIp} %{INT:sourcePort} %{IP:destIp} %{INT:destPort}"
1010
}
1111
patterns_dir => "./patterns/logstash_modsecurity_patterns"
1212
}
1313
}
14-
}
14+
}

logstash_modsecurity_patterns

Lines changed: 0 additions & 1 deletion
This file was deleted.

0 commit comments

Comments
 (0)