Files
zira-etc/crowdsec/patterns/tcpdump
2023-06-12 09:31:52 +03:00

2 lines
163 B
Plaintext

TCPDUMP_OUTPUT %{GREEDYDATA:timestamp} IP %{IPORHOST:source_ip}\.%{INT:source_port} > %{IPORHOST:dest_ip}\.%{INT:dest_port}: Flags \[%{GREEDYDATA:tcpflags}\], seq