cscli parsers install crowdsecurity/opnsense-gui-logs
A parser for opnsense web authentication (failed) logs.
Those logs are usually present in /var/log/audit/latest.log
.
1onsuccess: next_stage2filter: "evt.Parsed.program == 'audit'"3name: crowdsecurity/opnsense-gui-logs4description: "Parse OPNSense web auth logs"5#/index.php: Web GUI authentication error for 'toto' from 1.2.3.46grok:7 pattern: "/index.php: Web GUI authentication error for '%{USERNAME:username}' from %{IPORHOST:source_ip}"8 apply_on: message9statics:10 - meta: service11 value: opnsense-gui12 - meta: username13 expression: "evt.Parsed.username"14 - meta: source_ip15 expression: evt.Parsed.source_ip16 - meta: log_type17 value: opnsense-gui-failed-auth18