elastic / beats

:tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash
https://www.elastic.co/products/beats
Other
12.11k stars 4.91k forks source link

[Filebeat] Module for Ubiquiti Firewall Logs #8781

Closed andrewkroh closed 5 years ago

andrewkroh commented 5 years ago

As a user I want to be able to ingest firewall logs from Ubiquiti network gear. Ubiquiti firewall logs are essentially Linux iptables log message with a prefix that designates the source interface. In my experience the primary means of getting these logs is via syslog. Here are some samples (without the syslog header).

elasticmachine commented 5 years ago

Pinging @elastic/secops

jamesspi commented 5 years ago

@andrewkroh - plan on having a PR for this early Jan. Sorry for the delay!