--- /dev/null
+provisionalresults:
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:31
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "52809"
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:31
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "52809"
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ StrTime: Dec 17 14:31:31
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:31
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "443"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "52809"
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:31
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "443"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "52809"
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ StrTime: Dec 17 14:31:31
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:32
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53076"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53076"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "443"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "443"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "22"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "22"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "22"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "22"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:33
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:34
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53077"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53077"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:35
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3128"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3128"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3128"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3128"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53078"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53078"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- s00-raw:
+ crowdsecurity/syslog-logs:
+ ExpectMode: 1
+ Stage: s01-parse
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ facility: ""
+ logsource: syslog
+ message: '[66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ s01-parse:
+ crowdsecurity/iptables-logs:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ StrTime: Dec 17 14:31:36
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+ s02-enrich:
+ crowdsecurity/dateparse-enrich:
+ ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+finalresults:
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618940.661938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=28 ID=26921 PROTO=TCP SPT=52809 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "52809"
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ StrTime: Dec 17 14:31:31
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:31 sd-126005 kernel: [66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "443"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618940.662391] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=16966 PROTO=TCP SPT=52809 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "52809"
+ timestamp: Dec 17 14:31:31
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ StrTime: Dec 17 14:31:31
+ MarshaledTime: "2020-12-17T14:31:31Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.052919] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.052961] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=21005 PROTO=TCP SPT=53065 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053010] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053030] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=11372 PROTO=TCP SPT=53065 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=28944 PROTO=TCP SPT=53065 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053456] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=17445 PROTO=TCP SPT=53065 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5948 PROTO=TCP SPT=53065 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.053896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31577 PROTO=TCP SPT=53065 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=1732 PROTO=TCP SPT=53065 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054429] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=27362 PROTO=TCP SPT=53065 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:32 sd-126005 kernel: [66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618941.054922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=7677 PROTO=TCP SPT=53065 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:32
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ StrTime: Dec 17 14:31:32
+ MarshaledTime: "2020-12-17T14:31:32Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.149948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.149991] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=47324 PROTO=TCP SPT=53066 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151918] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151950] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=63400 PROTO=TCP SPT=53066 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.151995] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152012] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=21847 PROTO=TCP SPT=53066 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45327 PROTO=TCP SPT=53066 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152422] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=65406 PROTO=TCP SPT=53066 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=11370 PROTO=TCP SPT=53066 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152930] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=43957 PROTO=TCP SPT=53066 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152964] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.152980] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=42393 PROTO=TCP SPT=53066 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.153388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.153404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=17239 PROTO=TCP SPT=53066 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618942.246912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=43 ID=36687 PROTO=TCP SPT=53076 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53076"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.254936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.254957] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=2707 PROTO=TCP SPT=53065 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=9039 PROTO=TCP SPT=53065 DPT=80 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255411] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255414] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=4604 PROTO=TCP SPT=53065 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=21152 PROTO=TCP SPT=53065 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255905] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=52911 PROTO=TCP SPT=53065 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.255965] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=9177 PROTO=TCP SPT=53065 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "443"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256005] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=39157 PROTO=TCP SPT=53065 DPT=443 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=65075 PROTO=TCP SPT=53065 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.256466] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=24552 PROTO=TCP SPT=53065 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.351410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.351424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=63568 PROTO=TCP SPT=53066 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.445896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.445911] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=42946 PROTO=TCP SPT=53066 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446369] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=5294 PROTO=TCP SPT=53066 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=55671 PROTO=TCP SPT=53066 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=11447 PROTO=TCP SPT=53066 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=49319 PROTO=TCP SPT=53065 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446891] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446903] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=52041 PROTO=TCP SPT=53066 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.446944] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=26939 PROTO=TCP SPT=53066 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=37862 PROTO=TCP SPT=53065 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447440] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.447453] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=29147 PROTO=TCP SPT=53065 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.448399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.448413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=19463 PROTO=TCP SPT=53065 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.546912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.546926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21009 PROTO=TCP SPT=53065 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=11383 PROTO=TCP SPT=53065 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "22"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=59524 PROTO=TCP SPT=53065 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547515] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547526] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=29613 PROTO=TCP SPT=53065 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.547883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=17466 PROTO=TCP SPT=53066 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=10108 PROTO=TCP SPT=53066 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=22112 PROTO=TCP SPT=53065 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=10305 PROTO=TCP SPT=53066 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=62132 PROTO=TCP SPT=53065 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549922] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.549933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=42038 PROTO=TCP SPT=53066 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "22"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=38787 PROTO=TCP SPT=53066 DPT=22 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647447] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=2746 PROTO=TCP SPT=53066 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=10328 PROTO=TCP SPT=53066 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.647926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=13847 PROTO=TCP SPT=53066 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=51466 PROTO=TCP SPT=53066 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=4934 PROTO=TCP SPT=53065 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=24647 PROTO=TCP SPT=53065 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650948] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.650959] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13682 PROTO=TCP SPT=53066 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651381] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=36646 PROTO=TCP SPT=53065 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=45920 PROTO=TCP SPT=53065 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651909] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.651920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53823 PROTO=TCP SPT=53065 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751471] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=2612 PROTO=TCP SPT=53065 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751872] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=43986 PROTO=TCP SPT=53065 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751915] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=6902 PROTO=TCP SPT=53065 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751955] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.751966] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=61323 PROTO=TCP SPT=53065 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=64615 PROTO=TCP SPT=53066 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=5874 PROTO=TCP SPT=53066 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752458] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=17769 PROTO=TCP SPT=53066 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=46448 PROTO=TCP SPT=53066 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.752936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=56561 PROTO=TCP SPT=53065 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753368] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=18227 PROTO=TCP SPT=53066 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.753421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20655 PROTO=TCP SPT=53065 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=13466 PROTO=TCP SPT=53066 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.847877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=48855 PROTO=TCP SPT=53066 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848898] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=8240 PROTO=TCP SPT=53066 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848933] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.848946] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=27782 PROTO=TCP SPT=53066 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.849372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.849387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=44015 PROTO=TCP SPT=53066 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.850889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.850904] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=20430 PROTO=TCP SPT=53066 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851361] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=58492 PROTO=TCP SPT=53065 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851410] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851423] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=25226 PROTO=TCP SPT=53065 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851491] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851505] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=43292 PROTO=TCP SPT=53065 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:33 sd-126005 kernel: [66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618942.851884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=60598 PROTO=TCP SPT=53065 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:33
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ StrTime: Dec 17 14:31:33
+ MarshaledTime: "2020-12-17T14:31:33Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.952908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.952935] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=56711 PROTO=TCP SPT=53066 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=12918 PROTO=TCP SPT=53066 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953418] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3936 PROTO=TCP SPT=53066 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953468] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953489] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=9259 PROTO=TCP SPT=53066 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "10629"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.953868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=37279 PROTO=TCP SPT=53067 DPT=10629 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2393"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=7568 PROTO=TCP SPT=53067 DPT=2393 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:34 sd-126005 kernel: [66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1174"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618943.954427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=49596 PROTO=TCP SPT=53067 DPT=1174 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:34
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ StrTime: Dec 17 14:31:34
+ MarshaledTime: "2020-12-17T14:31:34Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618944.049409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=32937 PROTO=TCP SPT=53077 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53077"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2106"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051924] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44360 PROTO=TCP SPT=53067 DPT=2106 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051956] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.051967] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=19007 PROTO=TCP SPT=53067 DPT=7025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "264"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=45967 PROTO=TCP SPT=53067 DPT=264 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24800"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39778 PROTO=TCP SPT=53067 DPT=24800 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3030"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10156 PROTO=TCP SPT=53067 DPT=3030 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "407"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.052444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=59505 PROTO=TCP SPT=53067 DPT=407 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077892] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8192"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077906] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=9373 PROTO=TCP SPT=53067 DPT=8192 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "512"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.077949] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=56059 PROTO=TCP SPT=53067 DPT=512 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5051"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078364] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=10654 PROTO=TCP SPT=53067 DPT=5051 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2557"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078407] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=34768 PROTO=TCP SPT=53067 DPT=2557 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1055"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078446] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19037 PROTO=TCP SPT=53067 DPT=1055 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078473] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1533"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078485] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59379 PROTO=TCP SPT=53067 DPT=1533 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "256"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.078871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=37746 PROTO=TCP SPT=53067 DPT=256 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.079353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1087"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.079366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=25643 PROTO=TCP SPT=53067 DPT=1087 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "993"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153412] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=3771 PROTO=TCP SPT=53067 DPT=993 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153449] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "554"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153463] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64314 PROTO=TCP SPT=53067 DPT=554 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153499] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "139"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153512] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=61795 PROTO=TCP SPT=53067 DPT=139 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153543] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8888"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.153557] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3 PROTO=TCP SPT=53067 DPT=8888 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1025"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=35151 PROTO=TCP SPT=53067 DPT=1025 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5900"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.154860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44176 PROTO=TCP SPT=53067 DPT=5900 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "445"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=863 PROTO=TCP SPT=53067 DPT=445 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "587"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=60840 PROTO=TCP SPT=53067 DPT=587 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180474] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "8080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180486] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35713 PROTO=TCP SPT=53067 DPT=8080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180517] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1720"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180529] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=39355 PROTO=TCP SPT=53067 DPT=1720 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "111"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=23787 PROTO=TCP SPT=53067 DPT=111 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.180883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=15612 PROTO=TCP SPT=53067 DPT=135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181340] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "110"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=57696 PROTO=TCP SPT=53067 DPT=110 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1723"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.181393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=10534 PROTO=TCP SPT=53067 DPT=1723 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.253887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "53"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.253902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=15739 PROTO=TCP SPT=53067 DPT=53 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257374] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "113"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257389] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=54114 PROTO=TCP SPT=53067 DPT=113 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3306"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257432] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=55989 PROTO=TCP SPT=53067 DPT=3306 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "995"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257470] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=20758 PROTO=TCP SPT=53067 DPT=995 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257496] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "199"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257508] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=9311 PROTO=TCP SPT=53067 DPT=199 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "21"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.257857] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=22754 PROTO=TCP SPT=53067 DPT=21 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.278895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "143"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.278910] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=11918 PROTO=TCP SPT=53067 DPT=143 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279341] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3389"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=60660 PROTO=TCP SPT=53067 DPT=3389 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=22518 PROTO=TCP SPT=53065 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.279896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=32091 PROTO=TCP SPT=53067 DPT=23 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282384] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282399] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=62716 PROTO=TCP SPT=53065 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=55092 PROTO=TCP SPT=53065 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.282878] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=7092 PROTO=TCP SPT=53065 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=22356 PROTO=TCP SPT=53065 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352438] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=37504 PROTO=TCP SPT=53065 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352836] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=33164 PROTO=TCP SPT=53065 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.352907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=16518 PROTO=TCP SPT=53065 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.353357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.353370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=45991 PROTO=TCP SPT=53065 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.355921] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=56903 PROTO=TCP SPT=53065 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379419] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=61344 PROTO=TCP SPT=53065 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379451] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379462] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=31351 PROTO=TCP SPT=53066 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379490] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379502] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=20231 PROTO=TCP SPT=53065 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379534] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.379545] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=48502 PROTO=TCP SPT=53065 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=13692 PROTO=TCP SPT=53065 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.380865] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=5706 PROTO=TCP SPT=53066 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=56353 PROTO=TCP SPT=53066 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.381420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=49235 PROTO=TCP SPT=53066 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=59695 PROTO=TCP SPT=53066 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=3585 PROTO=TCP SPT=53066 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=43087 PROTO=TCP SPT=53066 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.452942] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=57388 PROTO=TCP SPT=53066 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453352] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=47706 PROTO=TCP SPT=53066 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.453855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=41171 PROTO=TCP SPT=53066 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=8287 PROTO=TCP SPT=53066 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=39498 PROTO=TCP SPT=53066 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=28828 PROTO=TCP SPT=53066 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.479894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=32209 PROTO=TCP SPT=53066 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16080"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480358] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=43341 PROTO=TCP SPT=53067 DPT=16080 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1062"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.480860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=57357 PROTO=TCP SPT=53067 DPT=1062 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1069"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=59674 PROTO=TCP SPT=53067 DPT=1069 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481436] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5440"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.481450] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=44572 PROTO=TCP SPT=53067 DPT=5440 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552888] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "55600"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=45754 PROTO=TCP SPT=53067 DPT=55600 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3689"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.552920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=62955 PROTO=TCP SPT=53067 DPT=3689 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "44176"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=34700 PROTO=TCP SPT=53067 DPT=44176 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554927] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "23502"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.554938] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=22568 PROTO=TCP SPT=53067 DPT=23502 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=56208 PROTO=TCP SPT=53067 DPT=6009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6646"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.555403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=7007 PROTO=TCP SPT=53067 DPT=6646 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.580881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "12000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.580895] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=24214 PROTO=TCP SPT=53067 DPT=12000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581339] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4129"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581351] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=31872 PROTO=TCP SPT=53067 DPT=4129 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581378] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "6969"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=15727 PROTO=TCP SPT=53067 DPT=6969 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581420] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5915"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=19909 PROTO=TCP SPT=53067 DPT=5915 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.581855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=64020 PROTO=TCP SPT=53065 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=5834 PROTO=TCP SPT=53065 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=20632 PROTO=TCP SPT=53065 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.582401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=60395 PROTO=TCP SPT=53065 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.673897] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.673912] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=3798 PROTO=TCP SPT=53065 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.674346] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.674359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=20726 PROTO=TCP SPT=53065 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683388] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683403] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=21455 PROTO=TCP SPT=53065 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.683855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=4183 PROTO=TCP SPT=53065 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684343] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=36370 PROTO=TCP SPT=53065 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.684393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=46179 PROTO=TCP SPT=53065 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.718886] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.718901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=13879 PROTO=TCP SPT=53066 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719330] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=52769 PROTO=TCP SPT=53065 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719839] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=6867 PROTO=TCP SPT=53065 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719877] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.719889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=10429 PROTO=TCP SPT=53065 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3001 PROTO=TCP SPT=53065 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723851] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=53098 PROTO=TCP SPT=53066 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.723864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=1053 PROTO=TCP SPT=53066 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.724344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.724356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=11254 PROTO=TCP SPT=53066 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.780887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.780902] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=10737 PROTO=TCP SPT=53066 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.781866] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.781901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=10794 PROTO=TCP SPT=53066 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=41061 PROTO=TCP SPT=53066 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782417] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=53322 PROTO=TCP SPT=53066 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782445] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782457] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=31174 PROTO=TCP SPT=53066 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5179 PROTO=TCP SPT=53066 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.782896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=27475 PROTO=TCP SPT=53066 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783376] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=32032 PROTO=TCP SPT=53066 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783409] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783421] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=15390 PROTO=TCP SPT=53066 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.783460] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=53695 PROTO=TCP SPT=53066 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.784357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "668"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.784371] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=8278 PROTO=TCP SPT=53067 DPT=668 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9968"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812394] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=21014 PROTO=TCP SPT=53067 DPT=9968 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1154"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812437] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=48843 PROTO=TCP SPT=53067 DPT=1154 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812469] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3333"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.812481] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=35037 PROTO=TCP SPT=53067 DPT=3333 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9418"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=30376 PROTO=TCP SPT=53067 DPT=9418 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874448] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1075"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874459] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=45 ID=22384 PROTO=TCP SPT=53067 DPT=1075 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874833] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1034"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.874845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=25457 PROTO=TCP SPT=53067 DPT=1034 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4006"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875366] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=40785 PROTO=TCP SPT=53067 DPT=4006 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3971"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=64076 PROTO=TCP SPT=53067 DPT=3971 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875433] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5060"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.875444] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=33279 PROTO=TCP SPT=53067 DPT=5060 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "18040"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=3453 PROTO=TCP SPT=53067 DPT=18040 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880415] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "30"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880426] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=55395 PROTO=TCP SPT=53067 DPT=30 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880830] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2119"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880842] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=50820 PROTO=TCP SPT=53067 DPT=2119 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1259"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.880881] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=51884 PROTO=TCP SPT=53067 DPT=1259 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=31472 PROTO=TCP SPT=53065 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881831] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=18935 PROTO=TCP SPT=53065 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881873] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.881885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=531 PROTO=TCP SPT=53065 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.882385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.882405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=25511 PROTO=TCP SPT=53065 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953434] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=44329 PROTO=TCP SPT=53065 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.953862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=45663 PROTO=TCP SPT=53065 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.954871] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.954884] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=20756 PROTO=TCP SPT=53065 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.955860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.955874] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=33563 PROTO=TCP SPT=53065 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956353] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956365] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=30095 PROTO=TCP SPT=53065 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956397] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:35 sd-126005 kernel: [66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.956408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=5421 PROTO=TCP SPT=53065 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:35
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ StrTime: Dec 17 14:31:35
+ MarshaledTime: "2020-12-17T14:31:35Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980400] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=31900 PROTO=TCP SPT=53066 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.980862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=25405 PROTO=TCP SPT=53065 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=59263 PROTO=TCP SPT=53065 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981826] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981837] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7121 PROTO=TCP SPT=53065 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981864] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.981876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=45771 PROTO=TCP SPT=53065 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982355] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=42164 PROTO=TCP SPT=53066 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982406] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=9953 PROTO=TCP SPT=53066 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982843] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618944.982856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=35212 PROTO=TCP SPT=53066 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053387] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053402] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=16126 PROTO=TCP SPT=53066 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053860] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.053894] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=45197 PROTO=TCP SPT=53066 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055879] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055893] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=45041 PROTO=TCP SPT=53066 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055926] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055937] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=35828 PROTO=TCP SPT=53066 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055982] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.055994] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=43 ID=60605 PROTO=TCP SPT=53066 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.056363] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.056375] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=18122 PROTO=TCP SPT=53066 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.079863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.079876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=12964 PROTO=TCP SPT=53066 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080350] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080362] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=12565 PROTO=TCP SPT=53066 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080392] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=9173 PROTO=TCP SPT=53066 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080431] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080443] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=56513 PROTO=TCP SPT=53066 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080838] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "82"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080852] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=7723 PROTO=TCP SPT=53067 DPT=82 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "903"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.080858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=30 ID=3999 PROTO=TCP SPT=53067 DPT=903 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082382] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1277"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082395] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=47718 PROTO=TCP SPT=53067 DPT=1277 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082427] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1022"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.082439] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=64264 PROTO=TCP SPT=53067 DPT=1022 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2009"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156404] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=34934 PROTO=TCP SPT=53067 DPT=2009 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156856] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2135"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.156869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=58179 PROTO=TCP SPT=53067 DPT=2135 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.157868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3260"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.157882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=40118 PROTO=TCP SPT=53067 DPT=3260 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "7741"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158380] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=31 ID=45385 PROTO=TCP SPT=53067 DPT=7741 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4125"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158424] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=41031 PROTO=TCP SPT=53067 DPT=4125 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158841] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "9103"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.158853] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21409 PROTO=TCP SPT=53067 DPT=9103 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180390] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "24444"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180405] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=14992 PROTO=TCP SPT=53067 DPT=24444 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180845] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180855] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "31038"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=32230 PROTO=TCP SPT=53067 DPT=31038 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "2161"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180868] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=50127 PROTO=TCP SPT=53067 DPT=2161 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180889] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3784"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.180901] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=52699 PROTO=TCP SPT=53067 DPT=3784 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181373] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181385] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=39299 PROTO=TCP SPT=53065 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181848] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.181861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=1486 PROTO=TCP SPT=53065 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182360] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=47 ID=41117 PROTO=TCP SPT=53065 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.182859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=40 ID=55019 PROTO=TCP SPT=53065 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3128"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.254882] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3128"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.254896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=56616 PROTO=TCP SPT=53065 DPT=3128 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.255345] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.255357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=638 PROTO=TCP SPT=53065 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256370] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256383] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=17341 PROTO=TCP SPT=53065 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256401] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=41301 PROTO=TCP SPT=53065 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256413] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256425] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=39511 PROTO=TCP SPT=53065 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256849] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.256861] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=59707 PROTO=TCP SPT=53065 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280372] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280386] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=19030 PROTO=TCP SPT=53066 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280835] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=19231 PROTO=TCP SPT=53065 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280875] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280887] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=38 ID=21935 PROTO=TCP SPT=53065 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280914] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.280925] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=30213 PROTO=TCP SPT=53065 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281359] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=44 ID=38092 PROTO=TCP SPT=53065 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53065"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281869] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.281883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=43580 PROTO=TCP SPT=53066 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282862] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282876] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=58412 PROTO=TCP SPT=53066 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282908] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.282920] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=44382 PROTO=TCP SPT=53066 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "80"
+ facility: ""
+ int_eth: enp1s0
+ length: "40"
+ logsource: syslog
+ message: '[66618945.355393] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=40 TOS=0x00 PREC=0x00 TTL=34 ID=43247 PROTO=TCP SPT=53078 DPT=80 WINDOW=1024 RES=0x00 ACK URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53078"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355850] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5414"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355863] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=9024 PROTO=TCP SPT=53066 DPT=5414 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355896] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4998"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355907] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=26819 PROTO=TCP SPT=53066 DPT=4998 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355936] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4567"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.355947] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=41140 PROTO=TCP SPT=53066 DPT=4567 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356334] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "3551"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356347] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=40874 PROTO=TCP SPT=53066 DPT=3551 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356847] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "16000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.356859] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=9300 PROTO=TCP SPT=53066 DPT=16000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380867] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380870] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "777"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380883] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=48 ID=29673 PROTO=TCP SPT=53066 DPT=777 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1721"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.380885] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=33 ID=47575 PROTO=TCP SPT=53066 DPT=1721 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381354] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "1166"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381367] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=40723 PROTO=TCP SPT=53066 DPT=1166 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381396] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5802"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381408] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=37 ID=22808 PROTO=TCP SPT=53066 DPT=5802 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53066"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381832] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "90"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.381844] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=28420 PROTO=TCP SPT=53067 DPT=90 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382344] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "5102"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382356] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=17357 PROTO=TCP SPT=53067 DPT=5102 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382846] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "705"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.382858] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=49 ID=8271 PROTO=TCP SPT=53067 DPT=705 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.383342] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93
+- ExpectMode: 1
+ Stage: s02-enrich
+ Line:
+ Raw: 'Dec 17 14:31:36 sd-126005 kernel: [66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ Src: ./collections/crowdsecurity/.tests/iptables/iptables.log
+ time: 0001-01-01T00:00:00Z
+ Labels:
+ type: syslog
+ process: true
+ Parsed:
+ action: ""
+ dst_ip: 51.15.166.67
+ dst_port: "4000"
+ facility: ""
+ int_eth: enp1s0
+ length: "44"
+ logsource: syslog
+ message: '[66618945.383357] IN=enp1s0 OUT= MAC=00:08:a2:0c:1f:12:00:c8:8b:e2:d6:87:08:00 SRC=42.42.42.93 DST=51.15.166.67 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=53657 PROTO=TCP SPT=53067 DPT=4000 WINDOW=1024 RES=0x00 SYN URGP=0 '
+ pid: ""
+ priority: ""
+ program: kernel
+ proto: TCP
+ src_ip: 42.42.42.93
+ src_port: "53067"
+ timestamp: Dec 17 14:31:36
+ timestamp8601: ""
+ Enriched:
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ StrTime: Dec 17 14:31:36
+ MarshaledTime: "2020-12-17T14:31:36Z"
+ Process: true
+ Meta:
+ log_type: iptables_drop
+ service: tcp
+ source_ip: 42.42.42.93