logstash-plugins / logstash-patterns-core

Apache License 2.0
2.17k stars 979 forks source link

Feat: ECS compliant Juniper (SRX) RT_FLOW captures #294

Closed kares closed 3 years ago

kares commented 3 years ago

These should be fairly straight-forward - Beats has a Juniper module.

There were no existing specs but according to Juniper KB these match unstructured SRX gateway logs.

NOTE: Beats only supports structured logs while here LS is aimed at parsing unstructured log lines. For better interoperability we follow the juniper.srx prefix naming for custom fields established by Beats.

kares commented 3 years ago

// cc @ebeahan @webmat if you get a chance for a quick field naming review - specs show-case the ecs captures