cscli parsers install crowdsecurity/exchange-smtp-logs
A parser for exchange SMTP protocol logs.
1filter: "evt.Parsed.program == 'exchange-smtp'"2onsuccess: next_stage3#debug: true4name: crowdsecurity/exchange-smtp-logs5description: "Parse exchange SMTP logs"6#date-time,connector-id,session-id,sequence-number,local-endpoint,remote-endpoint,event,data,context7#2022-04-28T13:24:50.200Z,EXCHANGE-1\Default Frontend EXCHANGE-1,08DA28A9AF671267,15,192.168.9.241:25,192.168.9.212:28657,>,535 5.7.3 Authentication unsuccessful,8grok:9 pattern: "%{TIMESTAMP_ISO8601:date},%{DATA:connector_id},%{DATA:session_id},%{INT:sequence_number},%{IPORHOST:server_ip}:%{INT:server_port},%{IPORHOST:client_ip}:%{INT:client_port},%{DATA:event},%{INT:smtp_code} [^ ]+ %{DATA:smtp_message},"10 apply_on: message11statics:12 - target: evt.StrTime13 expression: evt.Parsed.date14 - meta: source_ip15 expression: evt.Parsed.client_ip16 - meta: smtp_message17 expression: evt.Parsed.smtp_message18 - meta: service19 value: exchange20 - meta: log_type21 value: smtp22 - meta: sub_type23 value: auth_fail