cscli parsers install LePresidente/ombi-logs
Parser for Ombi Logs.
---
filenames:
- /var/log/ombi/log-*.txt
labels:
type: ombi
1onsuccess: next_stage2#debug: false3name: LePresidente/ombi-logs4description: "Parse ombi logs"5filter: "evt.Parsed.program == 'ombi'"6nodes:7 - grok:8 pattern: '%{TIMESTAMP_ISO8601:timestamp}.*?Failed login attempt by IP: %{IP:source_ip}'910 apply_on: message11 statics:12 - meta: log_type13 value: ombi_auth_failed1415statics:16 - meta: service17 value: ombi18 - meta: source_ip19 expression: "evt.Parsed.source_ip"20 - target: evt.StrTime21 expression: evt.Parsed.timestamp