datapunctum / TA-pfsense

Splunk Technology Add-On for pfsense
Apache License 2.0
11 stars 10 forks source link

DHCP extraction - device name #9

Closed mbistrom closed 3 years ago

mbistrom commented 4 years ago

May I suggest editing props.conf to include the device name (when available) in the DHCP-logs Change from EXTRACT-ipv4_dhcp = (?<vendor_action>DHCPACK|DHCPREQUEST) (?:on|for) (?<dest_ip>\S+) (?:from|to) (?<src_mac>\S+) \(.*\) via (?<src_interface>\S+) to EXTRACT-ipv4_dhcp = (?<vendor_action>DHCPACK|DHCPREQUEST) (?:on|for) (?<dest_ip>\S+) (?:from|to) (?<src_mac>\S+)(\s\((?<device_name>.*)\))? via (?<src_interface>\S+)

my2ndhead commented 3 years ago

Fixed with next release