imperva / incapsula-siem-package-graylog

Predefined SIEM application packages for Graylog which automate the loading of events from the Incapsula cloud into your SIEM
MIT License
3 stars 6 forks source link

Regex Extractors Catching "cs" From Following Field #7

Open reighnman opened 5 years ago

reighnman commented 5 years ago

The regex pattern in the majority of the extractors are catching the "cs" from the following field. For example, if capturing cs4Label it should just capture "VID" but ends up capturing "VID cs"

cs1=NA cs1Label=Cap Support cs4=cd736115-17e9-45b8-aa0e-6d9ff0a49b52 cs4Label=VID cs5Label=clappsig dproc=Browser cs6=Internet Explorer

graylog 3.1