Syslog fwevents and regex.
-
Hi all,
I wonder if anyone here can help me, but i ask anyway :)
I syslog my firewall events to my correlation engine and as you know ip's and port are preset is something like this 192.168.0.1.80 > 10.0.0.1.1024
now i want to filter out everything else, but not that portnumber in one regex line. Any suggestion how i do that?Br,
Ville
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.