Read in all the logs!
from_beginning = true csv_timestamp_column = "timestamp" csv_timestamp_format = "ts-syslog"
This commit is contained in:
parent
146d5aad0c
commit
63be77ce53
@ -11,7 +11,9 @@
|
||||
name_suffix = "_ipblock"
|
||||
data_format = "csv"
|
||||
csv_delimiter = ","
|
||||
from_beginning = false
|
||||
from_beginning = true
|
||||
csv_timestamp_column = "timestamp"
|
||||
csv_timestamp_format = "ts-syslog"
|
||||
csv_tag_columns = ["geoip_code","feed_name","src_ip"]
|
||||
csv_column_names = ["timestamp","rulenum","interface","friendlyname","action","ip_version","protocolid","protocol","src_ip","dest_ip","src_port","dest_port","direction","geoip_code","ip_alias_name","ip_evaluated","feed_name","resolvedhostname","clienthostname","asn","duplicateeventstatus"]
|
||||
|
||||
@ -19,8 +21,10 @@
|
||||
files = ["/var/log/pfblockerng/dnsbl.log"]
|
||||
name_suffix = "_dnsbl"
|
||||
data_format = "csv"
|
||||
from_beginning = false
|
||||
csv_delimiter = ","
|
||||
from_beginning = false
|
||||
csv_timestamp_column = "timestamp"
|
||||
csv_timestamp_format = "ts-syslog"
|
||||
csv_tag_columns = ["src_ip","tld"]
|
||||
csv_column_names = ["blocktype","timestamp","domain","src_ip","req_agent","blockmethod","blocklist","tld","feed_name","duplicateeventstatus"]
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user