-
Notifications
You must be signed in to change notification settings - Fork 32
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Showing
2 changed files
with
101 additions
and
61 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
161 changes: 100 additions & 61 deletions
161
tests/integration/test_analysisd/test_predecoder_stage/data/syslog_socket_input.yaml
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,71 +1,110 @@ | ||
--- | ||
- | ||
name: "Syslog date format 1" | ||
description: "Check valid input" | ||
- name: Syslog date format 1 | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "Dec 29 10:00:01 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"program_name":"sshd","timestamp":"Dec 29 10:00:01","hostname":"linux-agent"}' | ||
- | ||
name: "Syslog date format 2" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, | ||
"command": "log_processing", "parameters": {"location":"master->/var/log/syslog", | ||
"log_format": "syslog", "event": "Dec 29 10:00:01 linux-agent sshd[29205]: Invalid user blimey from | ||
18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: >- | ||
{"program_name":"sshd","timestamp":"Dec 29 | ||
10:00:01","hostname":"linux-agent"} | ||
- name: Syslog date format 2 | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "2015 Dec 29 10:00:01 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"program_name":"sshd","timestamp":"2015 Dec 29 10:00:01"}' | ||
- | ||
name: "Syslog date format for rsyslog" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"2015 Dec 29 10:00:01 linux-agent sshd[29205]: Invalid user blimey from | ||
18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"program_name":"sshd","timestamp":"2015 Dec 29 10:00:01"}' | ||
- name: Syslog date format for rsyslog | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "2009-05-22T09:36:46.214994-07:00 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"program_name":"sshd","timestamp":"2009-05-22T09:36:46.214994-07:00"}' | ||
- | ||
name: "Syslog date format for proftpd 1.3.5" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"2009-05-22T09:36:46.214994-07:00 linux-agent sshd[29205]: Invalid user | ||
blimey from 18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"program_name":"sshd","timestamp":"2009-05-22T09:36:46.214994-07:00"}' | ||
- name: Syslog date format for proftpd 1.3.5 | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "2015-04-16 21:51:02,805 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"program_name":"sshd","timestamp":"2015-04-16 21:51:02,80"}' | ||
- | ||
name: "Syslog date format for xferlog date format" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"2015-04-16 21:51:02,805 linux-agent sshd[29205]: Invalid user blimey | ||
from 18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"program_name":"sshd","timestamp":"2015-04-16 21:51:02,805"}' | ||
- name: Syslog date format for xferlog date format | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "Mon Apr 17 18:27:14 2006 1 64.160.42.130 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"timestamp":"Mon Apr 17 18:27:14 2006"}' | ||
- | ||
name: "Syslog date format for snort date format" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"Mon Apr 17 18:27:14 2006 1 64.160.42.130 linux-agent sshd[29205]: | ||
Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"timestamp":"Mon Apr 17 18:27:14 2006"}' | ||
- name: Syslog date format for snort date format | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "01/28-09:13:16.240702 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"timestamp":"01/28-09:13:16.240702"}' | ||
- | ||
name: "Syslog date format for suricata date format" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"01/28-09:13:16.240702 linux-agent sshd[29205]: Invalid user blimey from | ||
18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"timestamp":"01/28-09:13:16.240702"}' | ||
- name: Syslog date format for suricata date format | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "01/28/1979-09:13:16.240702 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"timestamp":"01/28/1979-09:13:16.240702"}' | ||
- | ||
name: "Syslog date format for apache log format" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"01/28/1979-09:13:16.240702 linux-agent sshd[29205]: Invalid user blimey | ||
from 18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"timestamp":"01/28/1979-09:13:16.240702"}' | ||
- name: Syslog date format for apache log format | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "[Fri Feb 11 18:06:35 2004] [warn] linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"timestamp":"Fri Feb 11 18:06:35 2004"}' | ||
- | ||
name: "Syslog date format for macos ULS --syslog output" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"[Fri Feb 11 18:06:35 2004] [warn] linux-agent sshd[29205]: Invalid user | ||
blimey from 18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"timestamp":"Fri Feb 11 18:06:35 2004"}' | ||
- name: Syslog date format for macos ULS --syslog output | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "2021-04-21 10:16:09.404756-0700 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"program_name":"sshd","timestamp":"2021-04-21 10:16:09.404756-0700"}' | ||
- | ||
name: "Syslog Umlaut date format" | ||
description: "Check valid input" | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"2021-04-21 10:16:09.404756-0700 linux-agent sshd[29205]: Invalid user | ||
blimey from 18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"program_name":"sshd","timestamp":"2021-04-21 10:16:09.404756-0700"}' | ||
- name: Syslog Umlaut date format | ||
description: Check valid input | ||
test_case: | ||
- | ||
input: '{"version": 1, "origin": {"name": "wazuh-logtest", "module": "wazuh-logtest"}, "command": "log_processing", "parameters": {"location":"master->/var/log/syslog", "log_format": "syslog", "event": "Mär 02 17:30:52 linux-agent sshd[29205]: Invalid user blimey from 18.18.18.18 port 48928", "token": "21218e6b"}}' | ||
output: '{"program_name":"sshd","timestamp":"Mär 02 17:30:5"}' | ||
- input: >- | ||
{"version": 1, "origin": {"name": "wazuh-logtest", "module": | ||
"wazuh-logtest"}, "command": "log_processing", "parameters": | ||
{"location":"master->/var/log/syslog", "log_format": "syslog", "event": | ||
"Mär 02 17:30:52 linux-agent sshd[29205]: Invalid user blimey from | ||
18.18.18.18 port 48928", "token": "21218e6b"}} | ||
output: '{"program_name":"sshd","timestamp":"Mär 02 17:30:5"}' |