cscli parsers install mwinters-stuff/mailu-admin-logs
Parser for the mailu admin containers logs to get rate limited authentication attempts.
1# debug: true2onsuccess: next_stage3name: mwinters-stuff/mailu-admin-logs4description: "Parse mailu-admin logs"5filter: "evt.Parsed.program == 'mailu-admin'"6grok:7 pattern: "\\[%{TIMESTAMP_ISO8601:timestamp8601},.*\\] WARNING in limiter: Authentication attempt from %{IP:source_ip} has been rate-limited."8 apply_on: message9statics:10 - meta: log_type11 value: mailu_admin_auth_attempt12 - meta: service13 value: mailu-admin14 - meta: source_ip15 expression: "evt.Parsed.source_ip"16 - target: evt.StrTime17 expression: "evt.Parsed.timestamp8601"18