Skip to content

[detect]: Journalctl sources MUST use syslog type #4098

@LaurenceJJones

Description

@LaurenceJJones

caddy-journal:
when:
- Systemd.UnitInstalled("caddy.service")
- len(Path.Glob("/var/log/caddy/*.log")) == 0
hub_spec:
collections:
- crowdsecurity/caddy
acquisition_spec:
filename: caddy.yaml
datasource:
source: journalctl
labels:
type: caddy
journalctl_filter:
- "_SYSTEMD_UNIT=caddy.service"

ref title

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions