Skip to content

Releases: ZachChristensen28/TA-linux_iptables

TA-linux_iptables v1.3.8

10 Jul 00:47
7418d95
Compare
Choose a tag to compare
  • Added sample configuration for the syslog sourcetype if IPtable data is mixed with syslog data.
  • Updated log_prefix field extraction to consider log prefixes surrounded with quotes.

TA-linux_iptables v1.3.7

20 Aug 16:40
31aa61d
Compare
Choose a tag to compare
  • fixed incorrect app value for UFW events - #5
  • updated regex for different UFW log formats - #8

TA-linux_iptables v1.3.6

21 Jul 04:26
7ec991a
Compare
Choose a tag to compare

Notice:
This updated simplifies the number of sourcetypes down to a single sourcetype (linux:iptables). Any existing reports/alerts/views that are utilizing the old sourcetypes ("linux:iptables:ufw" or "linux:iptables:firewalld") will be impacted. Verify before updating to this version.

  • added support for firewalld rich rules - #2
  • updated to only use the single sourcetype, 'linux:iptables'
  • updated action lookup to use wildcards

TA-linux_iptables v1.3.5

03 Nov 03:58
a2092f1
Compare
Choose a tag to compare

New

  • Adding support for Splunk Cloud