Hey Community,
I’m completly new into this things, but I have the challenge to parse a firewall activity log of a barracuda CG Firewall, and I have absolutley no idea, how to do that.
Maybe there is someone out there, who can give me a hands on in this topic
my syslog message looks like this
XXX-01 XXX-01/box_Firewall_Activity: Info XXX-01 Allow: LIN|TCP||10.105.9.144|51320|00:00:00:00:00:00|10.200.200.199|8080|webcache|bond0.999|OP-SRV-PX|0|10.105.9.144|10.200.200.199|0|1|0|0|0|0|mm1_user|||||
And the challenge is to seperate all the terms, seperated by a pipe, into different fields - like this
Firewall Name XXX-01
Action Allow
Type LIN
Protocoll TCP
srcIF
srcIP 10.105.9.144
srcPort 51320
srcMAC 00:00:00:00:00:00
dstIP 10.200.200.199
dstPort 8080
Service webcache
dstIF bond0.999
RULE OP-SRV-PX
info 0
srcNAT 10.105.9.144
dstNAT 10.200.200.199
duration 0
count 1
RXBytes 0
TXBytes 0
RXPackets 0
TXPackets 0
User mm1_user
Protocoll
App Target
Content
URL Category
br esqu