@@ -37,14 +37,14 @@ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["program"]
3737results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["source_ip"] == "2.57.122.209"
3838results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["suricata_alert_signature"] == "SURICATA TCPv4 invalid checksum"
3939results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["suricata_classification"] == "Generic Protocol Command Decode"
40- results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["suricata_rule_severity "] == "1"
40+ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["suricata_gid "] == "1"
4141results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["date"] == "07/11/2022"
4242results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["message"] == "07/11/2022-10:29:01.860293 [**] [1:2200074:2] SURICATA TCPv4 invalid checksum [**] [Classification: Generic Protocol Command Decode] [Priority: 3] {TCP} 2.57.122.209:28487 -> 172.31.18.55:80"
4343results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["suricata_alert_signature_rev"] == "2"
4444results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["time"] == "10:29:01.860293"
4545results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Parsed["dest_ip"] == "172.31.18.55"
4646results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Meta["suricata_alert_signature_id"] == "2200074"
47- results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Meta["suricata_rule_severity"] == "1 "
47+ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Meta["suricata_rule_severity"] == "3 "
4848results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Meta["datasource_path"] == "suricata-logs-fastlog.log"
4949results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Meta["datasource_type"] == "file"
5050results["s01-parse"]["crowdsecurity/suricata-fastlogs"][0].Evt.Meta["log_type"] == "suricata_alert"
@@ -62,7 +62,7 @@ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["source_po
6262results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["suricata_classification"] == "Attempted Information Leak"
6363results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["source_ip"] == "89.248.163.216"
6464results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["suricata_alert_signature"] == "ET SCAN Sipvicious Scan"
65- results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["suricata_rule_severity "] == "1"
65+ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["suricata_gid "] == "1"
6666results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["date"] == "07/11/2022"
6767results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["program"] == "suricata-fastlogs"
6868results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Parsed["rule_id"] == "2008578"
@@ -74,7 +74,7 @@ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Meta["service"] =
7474results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Meta["source_ip"] == "89.248.163.216"
7575results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Meta["sub_log_type"] == "suricata_alert_fast_log"
7676results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Meta["suricata_alert_signature_id"] == "2008578"
77- results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Meta["suricata_rule_severity"] == "1 "
77+ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Meta["suricata_rule_severity"] == "2 "
7878results["s01-parse"]["crowdsecurity/suricata-fastlogs"][1].Evt.Meta["datasource_path"] == "suricata-logs-fastlog.log"
7979results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Success == true
8080results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Parsed["proto"] == "TCP"
@@ -92,13 +92,13 @@ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Parsed["suricata_
9292results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Parsed["message"] == "07/11/2022-08:36:12.345430 [**] [1:2034567:1] ET HUNTING curl User-Agent to Dotted Quad [**] [Classification: Potentially Bad Traffic] [Priority: 2] {TCP} 172.31.18.55:57194 -> 169.254.169.254:80"
9393results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Parsed["source_ip"] == "172.31.18.55"
9494results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Parsed["source_port"] == "57194"
95- results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Parsed["suricata_rule_severity "] == "1"
95+ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Parsed["suricata_gid "] == "1"
9696results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["log_type"] == "suricata_alert"
9797results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["service"] == "suricata"
9898results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["source_ip"] == "172.31.18.55"
9999results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["sub_log_type"] == "suricata_alert_fast_log"
100100results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["suricata_alert_signature_id"] == "2034567"
101- results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["suricata_rule_severity"] == "1 "
101+ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["suricata_rule_severity"] == "2 "
102102results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["datasource_path"] == "suricata-logs-fastlog.log"
103103results["s01-parse"]["crowdsecurity/suricata-fastlogs"][2].Evt.Meta["datasource_type"] == "file"
104104results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Success == true
@@ -117,7 +117,7 @@ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Parsed["dest_port
117117results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Parsed["rule_id"] == "2034125"
118118results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Parsed["source_port"] == "36288"
119119results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Parsed["suricata_alert_signature_rev"] == "4"
120- results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Parsed["suricata_rule_severity "] == "1"
120+ results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Parsed["suricata_gid "] == "1"
121121results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Meta["service"] == "suricata"
122122results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Meta["source_ip"] == "185.7.214.104"
123123results["s01-parse"]["crowdsecurity/suricata-fastlogs"][3].Evt.Meta["sub_log_type"] == "suricata_alert_fast_log"
@@ -130,7 +130,7 @@ len(results["s02-enrich"]["crowdsecurity/dateparse-enrich"]) == 4
130130results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Success == true
131131results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["date"] == "07/11/2022"
132132results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["suricata_priority"] == "3"
133- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["suricata_rule_severity "] == "1"
133+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["suricata_gid "] == "1"
134134results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["dest_ip"] == "172.31.18.55"
135135results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["rule_id"] == "2200074"
136136results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["source_port"] == "28487"
@@ -151,7 +151,7 @@ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["source_ip"]
151151results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["sub_log_type"] == "suricata_alert_fast_log"
152152results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["service"] == "suricata"
153153results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["suricata_alert_signature_id"] == "2200074"
154- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["suricata_rule_severity"] == "1 "
154+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["suricata_rule_severity"] == "3 "
155155results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["timestamp"] == "2022-07-11T10:29:01.860293Z"
156156results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Enriched["MarshaledTime"] == "2022-07-11T10:29:01.860293Z"
157157results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Success == true
@@ -170,15 +170,15 @@ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["suricata_
170170results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["source_ip"] == "89.248.163.216"
171171results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["source_port"] == "5116"
172172results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["date"] == "07/11/2022"
173- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["suricata_rule_severity "] == "1"
173+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["suricata_gid "] == "1"
174174results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["datasource_path"] == "suricata-logs-fastlog.log"
175175results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["log_type"] == "suricata_alert"
176176results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["service"] == "suricata"
177177results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["sub_log_type"] == "suricata_alert_fast_log"
178178results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["datasource_type"] == "file"
179179results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["source_ip"] == "89.248.163.216"
180180results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["suricata_alert_signature_id"] == "2008578"
181- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["suricata_rule_severity"] == "1 "
181+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["suricata_rule_severity"] == "2 "
182182results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["timestamp"] == "2022-07-11T10:29:32.251216Z"
183183results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Enriched["MarshaledTime"] == "2022-07-11T10:29:32.251216Z"
184184results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Success == true
@@ -191,7 +191,7 @@ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["suricata_
191191results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["dest_port"] == "80"
192192results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["suricata_alert_signature"] == "ET HUNTING curl User-Agent to Dotted Quad"
193193results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["suricata_alert_signature_rev"] == "1"
194- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["suricata_rule_severity "] == "1"
194+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["suricata_gid "] == "1"
195195results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["suricata_classification"] == "Potentially Bad Traffic"
196196results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["suricata_timestamp"] == "07/11/2022 08:36:12.345430"
197197results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Parsed["date"] == "07/11/2022"
@@ -206,13 +206,13 @@ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Meta["log_type"]
206206results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Meta["timestamp"] == "2022-07-11T08:36:12.34543Z"
207207results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Meta["source_ip"] == "172.31.18.55"
208208results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Meta["sub_log_type"] == "suricata_alert_fast_log"
209- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Meta["suricata_rule_severity"] == "1 "
209+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Meta["suricata_rule_severity"] == "2 "
210210results["s02-enrich"]["crowdsecurity/dateparse-enrich"][2].Evt.Enriched["MarshaledTime"] == "2022-07-11T08:36:12.34543Z"
211211results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Success == true
212212results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["message"] == "07/11/2022-06:09:52.602489 [**] [1:2034125:4] ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2 [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 185.7.214.104:36288 -> 172.31.18.55:80"
213213results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["suricata_alert_signature_rev"] == "4"
214214results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["suricata_priority"] == "1"
215- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["suricata_rule_severity "] == "1"
215+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["suricata_gid "] == "1"
216216results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["program"] == "suricata-fastlogs"
217217results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["rule_id"] == "2034125"
218218results["s02-enrich"]["crowdsecurity/dateparse-enrich"][3].Evt.Parsed["source_port"] == "36288"
0 commit comments