cscli parsers install crowdsecurity/cowrie-logs
1onsuccess: next_stage2name: cowrie-logs3description: "Parse cowrie honeypots logs"4filter: "evt.Parsed.program == 'cowrie'"5grok:6 name: "COWRIE_NEW_CO"7 apply_on: message8statics:9 - meta: service10 value: telnet11 - meta: log_type12 value: telnet_new_session13 - meta: source_ip14 expression: "evt.Parsed.source_ip"15 - meta: dest_ip16 expression: "evt.Parsed.dest_ip"17 - meta: dest_port18 expression: "evt.Parsed.dest_port"19 - parsed: "telnet_session"20 expression: "evt.Parsed.telnet_session"