cscli parsers install crowdsecurity/thehive-logs
Thehive authentication failure parser.
Reference: https://docs.strangebee.com/thehive/setup/
1onsuccess: next_stage2name: crowdsecurity/thehive-logs3description: "Parse Thehive logs"4filter: "evt.Parsed.program == 'thehive'"5nodes:6 - grok:7 pattern: '\[info\] o.t.s.AccessLogFilter \[.*\] %{IP:source_ip} POST /api/v1/login took %{INT}ms and returned 401 %{INT} bytes'8 apply_on: message9statics:10 - meta: log_type11 value: thehive_failed_auth12 - meta: source_ip13 expression: "evt.Parsed.source_ip"14 - target: evt.StrTime15 value: toto