Files
vs/siem-elastic-template/elastic/parsers.conf
Gašper Dobrovoljc cfac75516b SIEM
2025-11-20 10:42:06 +01:00

8 lines
321 B
Plaintext

[PARSER]
Name http_access_custom
Format regex
Regex ^(?<host>\S+)\s+(?<ident>\S+)\s+(?<user>\S+)\s+\[(?<time>[^\]]+)\]\s+"(?<method>\S+)\s+(?<path>\S+)\s+(?<protocol>[^"]+)"\s+(?<code>\d{3})\s+(?<size>\S+)$
Time_Key time
Time_Format %d/%b/%Y %H:%M:%S
Types code:integer