Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
okatsladz454
Contributor

Time filtering fw1-loggrabber

Good afternoon.

 

The task is to create a time filter for collecting logs from a certain date (14 days before the collection is initiated) in the LEA log collection system.

Please tell me which filtering parameters and how to change them in fw1-loggrabber.conf in order to implement this mechanism?

Examples from fw-loggrabber.conf file (is there any chance of getting a complete list of possible filters) :


# FW1_FILTER_RULE=<rule>
#FW1_FILTER_RULE="action=drop"

# AUDIT_FILTER_RULE=<rule>
#AUDIT_FILTER_RULE="action=accept"

 

PS: please do not suggest switching to LogExporter, We can not implement it.

 

0 Kudos
1 Reply
okatsladz454
Contributor

https://github.com/certego/fw1-loggrabber/blob/master/fw1-loggrabber.conf

loggrabber conf Example, which i want to use to solve this task

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 18 Mar 2025 @ 09:30 AM (EET)

    CheckMates Live Greece

    Tue 25 Mar 2025 @ 12:00 PM (MDT)

    Salt Lake City: CPX 2025 Recap

    Tue 08 Apr 2025 @ 12:00 PM (MDT)

    Denver: CPX 2025 Recap
    CheckMates Events