We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 2ab4a07 commit 27f459cCopy full SHA for 27f459c
parsers/s01-parse/firewallservices/pf-logs.yaml
@@ -39,7 +39,7 @@ description: "Identify dropped packets"
39
onsuccess: next_stage
40
statics:
41
- meta: service
42
- expression: "evt.Parsed.ip4_proto != nil ? evt.Parsed.ip4_proto : evt.Parsed.ip6_proto"
+ expression: "Lower(evt.Parsed.ip4_proto != '' ? evt.Parsed.ip4_proto : evt.Parsed.ip6_proto)"
43
- meta: log_type
44
value: pf_drop
45
- meta: source_ip
0 commit comments