Commit 0cd4943
committed
Replace GREEDYDATA with DATA pattern for SMB IP parsing
- Removed SMB_IP_PORT custom pattern
- Use standard DATA pattern for ip_source_with_port extraction
- Extract IP using lastIndexOf expression to handle IPv6 addresses with ports
- Pattern now works correctly for both IPv4 and IPv6 addresses1 parent 300589b commit 0cd4943
File tree
3 files changed
+4
-4
lines changed- .tests/smb-logs
- parsers/s01-parse/crowdsecurity
3 files changed
+4
-4
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
| 6 | + | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
0 commit comments