cscli parsers install LearningSpot/dockge-logs
Parser for Dockge Logs with Docker.
---
source: docker
container_name:
- dockge
labels:
type: dockge
1name: LearningSpot/dockge-logs2description: "Parse Dockge Logs"3filter: "evt.Parsed.program == 'dockge'"4onsuccess: next_stage5nodes:6 - grok:7 pattern: '%{TIMESTAMP_ISO8601:timestamp} \[AUTH\] WARN: Incorrect username or password for user %{DATA:username}.? IP=%{IP:source_ip}'8 apply_on: message9 statics:10 - meta: log_type11 value: dockge_failed_auth12 - target: evt.StrTime13 expression: evt.Parsed.timestamp14 - meta: username15 expression: evt.Parsed.username16statics:17 - meta: service18 value: dockge19 - meta: source_ip20 expression: evt.Parsed.source_ip21