cscli parsers install crowdsecurity/postscreen-logs
1onsuccess: next_stage2filter: "evt.Parsed.program in ['postfix/postscreen', 'haproxy/postscreen']"3name: crowdsecurity/postscreen-logs4pattern_syntax:5 POSTSCREEN_PREGREET: 'PREGREET'6 POSTSCREEN_PREGREET_TIME_ATTEMPT: '\d+(.\d+)?'7description: "Parse postscreen logs"8nodes:9 - grok:10 apply_on: message11 pattern: '%{POSTSCREEN_PREGREET:pregreet} %{INT:count} after %{POSTSCREEN_PREGREET_TIME_ATTEMPT:time_attempt} from \[%{IP:remote_addr}\]:%{INT:port}: %{GREEDYDATA:message_attempt}'12statics:13 - meta: service14 value: postscreen15 - meta: source_ip16 expression: "evt.Parsed.remote_addr"17 - meta: pregreet18 expression: "evt.Parsed.pregreet"192021