cscli parsers install crowdsecurity/configserver-lfd-logs
Parser for ConfigSerer LFD file logs.
1onsuccess: next_stage2filter: "evt.Parsed.program == 'lfd'"3name: crowdsecurity/configserver-lfd-logs4description: "Parse ConfigServer LFD logs"5grok:6 pattern: "Failed SSH login from %{IP:source_ip} \\(%{NOTSPACE:country_code}/%{GREEDYDATA:country_name}/%{NOTSPACE:source_rdns}\\): %{GREEDYDATA:reason}"7 apply_on: message8 statics:9 - meta: source_ip10 expression: "evt.Parsed.source_ip"11 - meta: reason12 expression: "evt.Parsed.reason"