HEX

Warning: set_time_limit() [function.set-time-limit]: Cannot set time limit - prohibited by configuration in /home/u547966/brikov.ru/www/wp-content/plugins/admin-menu-editor/menu-editor.php on line 745
Server: Apache
System: Linux 4.19.0-0.bpo.9-amd64 x86_64 at red40
User: u547966 (5490)
PHP: 5.3.29-mh2
Disabled: syslog, dl, popen, proc_open, proc_nice, proc_get_status, proc_close, proc_terminate, posix_mkfifo, chown, chgrp, accelerator_reset, opcache_reset, accelerator_get_status, opcache_get_status, pcntl_alarm, pcntl_fork, pcntl_waitpid, pcntl_wait, pcntl_wifexited, pcntl_wifstopped, pcntl_wifsignaled, pcntl_wifcontinued, pcntl_wexitstatus, pcntl_wtermsig, pcntl_wstopsig, pcntl_signal, pcntl_signal_dispatch, pcntl_get_last_error, pcntl_strerror, pcntl_sigprocmask, pcntl_sigwaitinfo, pcntl_sigtimedwait, pcntl_exec, pcntl_getpriority, pcntl_setpriority
Upload Files
File: //usr/share/filebeat/module/panw/panos/ingest/globalprotect.yml
---
description: Pipeline for PanOS Global Protect Logs
processors:
  - set:
      field: source.ip
      value: "{{_temp_.private_ipv6}}"
      if: (ctx.source?.ip == null || ctx.source?.ip == "0.0.0.0") && ctx._temp_?.private_ipv6 != null && ctx._temp_?.private_ipv6 != "0.0.0.0"
  - set:
      field: source.nat.ip
      value: "{{_temp_.public_ipv6}}"
      if: (ctx.source?.nat?.ip == null || ctx.source?.nat?.ip == "0.0.0.0") && ctx._temp_?.public_ipv6 != null && ctx._temp_?.public_ipv6 != "0.0.0.0"
  - grok:
      field: _temp_.srcuser
      ignore_missing: true
      patterns:
        - '%{HOSTNAME:source.user.domain}\\%{USERNAME:source.user.name}'
        - '%{USERNAME:source.user.name}@%{HOSTNAME:source.user.domain}'
        - '%{USERNAME:source.user.name}'
      if: ctx?._temp_?.srcuser != null
  - set:
      field: network.type
      value: 'ipv4'
      if: 'ctx.network?.type == null && ctx.source?.ip != null && ctx.source.ip.contains(".")'
  - set:
      field: network.type
      value: 'ipv6'
      if: 'ctx.network?.type == null && ctx.source?.ip != null && ctx.source.ip.contains(":")'

on_failure:
  - append:
      field: error.message
      value: >-
        error in Global Protect pipeline:
        error in [{{_ingest.on_failure_processor_type}}] processor{{#_ingest.on_failure_processor_tag}}
        with tag [{{_ingest.on_failure_processor_tag }}]{{/_ingest.on_failure_processor_tag}}
        {{ _ingest.on_failure_message }}