Skip to content

Commit

Permalink
Add "else" catchall clause to zscaler-lss
Browse files Browse the repository at this point in the history
* Add "else" catchall clause to `lp-zscaler_lss.conf.tmpl`
  • Loading branch information
Mark Bonsack committed Apr 21, 2020
1 parent 56aaf66 commit 7414386
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions package/etc/conf.d/log_paths/lp-zscaler_lss.conf.tmpl
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,15 @@ log {
parser { p_add_context_splunk(key("zscaler_lss")); };
parser (compliance_meta_by_source);
rewrite { set("$(template ${.splunk.sc4s_template} $(template t_msg_only))" value("MSG")); };
} else {
rewrite {
set("zscaler_lss_rogue_message", value("fields.sc4s_vendor_product"));
set("Possible rogue message on zscaler_lss unique port", value("fields.sc4s_error"));
r_set_splunk_dest_default(sourcetype("zscalerlss:rogue"), index("netproxy"))
};
parser { p_add_context_splunk(key("zscaler_lss")); };
parser (compliance_meta_by_source);
rewrite { set("$(template ${.splunk.sc4s_template} $(template t_msg_only))" value("MSG")); };
};


Expand Down

0 comments on commit 7414386

Please sign in to comment.