Skip to content

Added non-standard Sophos UTM syslog timestamp format to pre-decoding.#1794

Merged
ddpbsd merged 1 commit intoossec:masterfrom
mwidman:master
Nov 19, 2019
Merged

Added non-standard Sophos UTM syslog timestamp format to pre-decoding.#1794
ddpbsd merged 1 commit intoossec:masterfrom
mwidman:master

Conversation

@mwidman
Copy link
Contributor

@mwidman mwidman commented Nov 15, 2019

The Sophos UTM firewall uses syslog to transmit data but uses a non-standard timestamp format that looks like: 2019:11:06-00:08:03. Outside of the timestamp, all other aspects appear to be the same as regular syslog entries so it makes sense to me to parse it as such.

@ddpbsd ddpbsd merged commit 160c6d4 into ossec:master Nov 19, 2019
@ddpbsd
Copy link
Member

ddpbsd commented Nov 19, 2019

Thanks for the pull request!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants