-
Notifications
You must be signed in to change notification settings - Fork 460
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[citrix_adc] Support addition log message types and ECS mappings (#11781
) Improve Citrix ADC integration log parsing and ECS mappings. Changes are: - Support "Mapped Ip" as value for Nat_Ip in all patterns in the sslvpn pipeline - Add support for additional "Message" subtypes, and add a "DATA" wildcard that will capture all patterns. All valid "Message" patterns are not known, so it's better to capture all without parsing individual fields than to cause an error. - Add addition ECS mappings for event.kind, event.outcome, observer.hostname - Calculate event.duration as the difference from event.start and event.end
- Loading branch information
Showing
11 changed files
with
508 additions
and
111 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.