I'm testing customizing the processing of my firewall logs. I started with creating a decoder etc/local_decoder.xml
Code: Select all
<decoder name="cisco-asa">
<prematch_pcre2>%ASA-\d-\d{6}</prematch_pcre2>
</decoder>
<decoder name="cisco_asa-syslogdecode">
<parent>cisco-asa</parent>
<regex>%ASA-(\S+)-(\S+):</regex>
<order>cisco_prio, cisco_code</order>
</decoder>
Next I tried rules in rules/local_rules.xml:
Code: Select all
<group name="local,syslog,errors,">
<rule id="100000" level="0">
<decoded_as>cisco-asa</decoded_as>
<description>cisco asa</description>
</rule>
</group>
Code: Select all
rules_list: Category '1' not found. Invalid 'category'.
//Tonny