Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

parser for log source Sucuri #2460

Open
narsree1 opened this issue May 13, 2024 · 2 comments
Open

parser for log source Sucuri #2460

narsree1 opened this issue May 13, 2024 · 2 comments

Comments

@narsree1
Copy link

**What is the sc4s version? 3.23.0

**Is there a pcap available? If so, would you prefer to attach it to this issue or send it to Splunk support? No

**What the vendor name? Sucuri

**What's the product name? WAF

**If you're requesting support for a new vendor, do you have any preferences regarding the default index and sourcetype for their events? index:Sucuri , Sourcetype: sucuri:alert

**Do you have syslog documentation or a manual for that device??https://docs.sucuri.net/website-firewall/configuration/integrating-with-splunk/

**Feature Request description: create a parser to parse events for Sucuri

**Do you want to have it for local usage or prepare a github PR? local usage

@mstopa-splunk
Copy link
Contributor

hi @narsree1 the log format provided in the attached documentation doesn't seem to be right and they provided only one example. Can you fetch more examples to a pcap file?

@ikheifets-splunk
Copy link
Contributor

ikheifets-splunk commented May 27, 2024

It seems that we haven't any activity during last 2 weeks.
@narsree1 can you please share pcap file (with logs that producing your Sucuri device), you can send me on email ikheifets@splunk.com

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants