mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 09:12:45 +01:00
fix pfsense firewall udp parsing
This commit is contained in:
@@ -34,7 +34,7 @@
|
||||
},
|
||||
{
|
||||
"dissect": {
|
||||
"if": "ctx.protocol == 'udp'",
|
||||
"if": "ctx.network?.transport == 'udp'",
|
||||
"field": "ip_sub_msg",
|
||||
"pattern" : "%{source.port},%{destination.port},%{data.length}",
|
||||
"on_failure" : [ {"set" : {"field" : "error.message","value" : "{{ _ingest.on_failure_message }}"}}]
|
||||
|
||||
Reference in New Issue
Block a user