Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Verac
Participant

Exclude IP and port from log_exporter

Hello all,

 

I am trying to trim up what logs I am sending to my SIEM. Currently I am sending all logs.

 

I've identified a particular IP and port that accounts for 30% of all logs sent.

I can't figure out how (or if you even can) send exclude an IP/port combo, but I can't even seem to get it to filter out just the destination IP.

Here is what I put into my filter config. after restarting the exporter I still am getting logs with the destination IP I tried to filter:

(Modified the IP for privacy)

<filters>
<filterGroup operator="and">
<field name="action" operator="and">
</field>
<field name="origin" operator="and">
</field>
<field name="product" operator="and">
</field>
<field name="dst_ip" operator="and">
<value operation="neq">192.168.1.1</value>
</field>
</filterGroup>
</filters>

 

Any help excluding that destination IP is appreciated, and even more so if I can exclude all packets with a dst and a certain port.

 

Thanks!

3 Replies
the_rock
Legend
Legend

Could you try set up a rule for specific IP or port you dont want logged and then set log action to none, apply policy and test?

Andy

Verac
Participant

I thought about doing that but was trying to exclude it with the log forwarder first and then take that route if I'm not able to to exclude just the forwarding.

the_rock
Legend
Legend

What file exactly did you modify?

 

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events