Files
zira-etc/crowdsec/patterns/mcollective
2023-06-12 09:31:52 +03:00

4 lines
189 B
Plaintext

# Remember, these can be multi-line events.
MCOLLECTIVE ., \[%{TIMESTAMP_ISO8601:timestamp} #%{POSINT:pid}\]%{SPACE}%{LOGLEVEL:event_level}
MCOLLECTIVEAUDIT %{TIMESTAMP_ISO8601:timestamp}: