Compilation of log collection plug-in for H3C Huasan switch based on OSSIM platform
Compilation of log collection plug-in for H3C Huasan switch based on OSSIM platform
On the basis of the previous article "Development of log collection plug-ins for switches based on the OSSIM platform", let's continue to share the contents of the H3C switch plug-ins:
[DEFAULT]
Plugin_id=1712
[config]
Type=detector
Enable=yes
Source=log
Location=/var/log/h4c-switch.log
Create_file=yes
Process=
Start=no
Stop=no
Restart=no
Startup=
Shutdown=
[translation]
CLKCHANGE=1
NTP_LOG=2
PFWD=3
PHONY_MODULE=4
RX_POW_NORMAL=5
RX_POW_LOW=6
LOGOUT=7
LOGINFAIL=8
[0001-H3C-ETH-SWITCH LOGIN LOGOUT]
Event_type=event
Precheck= "because"
Regexp= "(? P\ w {3}\ s +\ d:\ d\ d:\ d:\ d\ d)\ s +\ s + (? P\ S+)\ s +\%\ d + (? P\ S+)\ / (? P\ d +) / (? PLOGOUT | LOGINFAIL)\ (\ w+\)\:\ s + (? P [Amurz] +). \ d {1pr 3}). *? because\ s?\: (? P.*) "
Date= {normalize_date ($date)}
Plugin_sid= {translate ($sid)}
Device= {$host}
Src_ip= {$client_ip}
Userdata1= {$module}
Userdata2= {$severity}
Userdata3= {$reason}
Userdata4= {$service}
[0002-H3C-ETH-SWITCH]
Event_type=event
Regexp= "(? P\ w {3}\ s +\ d:\ d\ d)\ s +\ s + (? P\ S+)\ s +\%\%\ d + (? P\ S+)\ / (? P\ S+)\ (. *?\: (? P.*)"
Date= {normalize_date ($date)}
Plugin_sid= {translate ($sid)}
Device= {$host}
Userdata1= {$module}
Userdata2= {$severity}
Userdata3= {$explanation}
For information about collecting logs based on plug-ins, you can refer to the book "Open Source Security Operation and maintenance platform OSSIM Best practices".