Refine your search:

I'm trying to extract the fields of the mcafee ips syslogs being sent to Splunk. Here is a raw log if someone can help me create the regex. Still learning up about this.

7:00:51.000 PM Dec 6 19:00:53 192.168.1.30 SyslogAlertForwarder: 2011-12-06 19:00:51 EST Medium Mcafee-Sensor-01 ARP: ARP Spoofing Detected 0x42400100 N/A N/A N/A PolicyViolation Outbound Suspicious N/A N/A

host=shared-syslog-001.server.company.com Options| sourcetype=mcafee_ips Options| source=/var/log/syslog/system-192.168.1.30.log Options

asked 06 Dec '11, 16:08

kcobrien1's gravatar image

kcobrien1
11
accept rate: 0%


2 Answers:

index=XXX sourcetype=mcafee_ips | rex ".s(?<alert_level>S?)s(?<device>S?)s(?<proto_class>S?):(?<message>.?)s(?<hex>dx.?)ss?(?<src>.?)s(?<dst>.?)s(?<port>d?)s(?<policy>S?)s(?<direction>S?)s(?<status>(Blocked|Maybesuccessful|Suspicious|Successful))s(?<proto_l7>.?)s(?<proto_l4>.*?)$"

Still working this puppy but this will break out the fields so you can start choosing what you want to do next. More to come.

link

answered 07 Dec '11, 10:02

kcobrien1's gravatar image

kcobrien1
11
accept rate: 0%

Successful exploits

index=XXX sourcetype=mcafee_ips | rex ".s(?<alert_level>S?)s(?<device>S?)s(?<proto_class>S?):(?<message>.?)s(?<hex>dx.?)ss?(?<src>.?)s(?<dst>.?)s(?<port>d?)s(?<policy>S?)s(?<direction>S?)s(?<status>(Blocked|Maybesuccessful|Suspicious|Successful))s(?<proto_l7>.?)s(?<proto_l4>.*?)$" | search policy="Exploit" status="Successful"

link

answered 07 Dec '11, 10:52

kcobrien1's gravatar image

kcobrien1
11
accept rate: 0%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×23
×6

Asked: 06 Dec '11, 16:08

Seen: 1,494 times

Last updated: 07 Dec '11, 10:52

Copyright © 2005-2012 Splunk Inc. All rights reserved.