fix pfsense firewall udp parsing

This commit is contained in:
Doug Burks
2020-10-10 07:38:47 -04:00
committed by GitHub
parent 8cfabf101c
commit 8d1ba1f4db

View File

@@ -34,7 +34,7 @@
}, },
{ {
"dissect": { "dissect": {
"if": "ctx.protocol == 'udp'", "if": "ctx.network?.transport == 'udp'",
"field": "ip_sub_msg", "field": "ip_sub_msg",
"pattern" : "%{source.port},%{destination.port},%{data.length}", "pattern" : "%{source.port},%{destination.port},%{data.length}",
"on_failure" : [ {"set" : {"field" : "error.message","value" : "{{ _ingest.on_failure_message }}"}}] "on_failure" : [ {"set" : {"field" : "error.message","value" : "{{ _ingest.on_failure_message }}"}}]