Graylog_Extractors_pfSense
Graylog_Extractors_pfSense copied to clipboard
Update pfSense Extractors.json
added case ignore for protocol. I only have lowercase, rule is uppercase.
My Graylog/pfSense system is currently down as I'm moving, so I'm unable to test this.
Just looking at the edit you did though, I'm not understanding what "(?i)" prepended to the "UDP" should do. From what I understand that should just be a passive capture of an "i" in front of "UDP". That makes no sense. Can you direct me to something that explains the regex you used there?
It was a copy and paste job from stackoverflow i'm afraid. I tried without question mark and the extractor didn't match on my system. I'll leave you to test properly.
Doing some testing myself on the following:
^filterlog:\\s+.*,(in|out),4,.*,(?i)UDP,.*$
This will not work you need to remove a slash:
^filterlog:\s+.*,(in|out),4,.*,(?i)UDP,.*$
you can see the gist of this regex here: https://goo.gl/R288wp