help
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <20493257.1168571234878716145.JavaMail.defaultUser@defaultHost> |
I have to parse checkpoint log files. The problem is that seems that the format is different from those of checkpoint.rules of prelude-lml the format is "Number" "Date" "Time" "Interface" "Origin" "Type" "Action" "Service" "Source Port" "Source" "Destination" "Protocol" "Rule" "Rule Name" "Current Rule Number" "User" "Information" "Product" some line examples are "6513864" "16Feb2009" "0:00:00" "eth0.18" "CP_FW5_01" "Log" "Drop" "15200" "14910" "xxx.xxx.xxx.xxx" "NAT_management" "udp" "24" "" "24-FW5_Startup_20_05_2008" "" "" "VPN-1 Power/UTM" "6513865" "16Feb2009" "0:00:00" "eth0.18" "CP_FW5_01" "Log" "Drop" "11373" "12705" "xxx.xxx.xxx.xxx" "NAT_management" "udp" "24" "" "24-FW5_Startup_20_05_2008" "" "" "VPN-1 Power/UTM" "6513869" "16Feb2009" "0:00:00" "eth0.70" "CP_FW2_01" "Log" "Drop" "42587" "36115" "xxx.xxx.xxx.xxx" "CP_FW2" "tcp" "22" "" "22- FW2_StartPolicy_16_05_2008" "" "" "VPN-1 Power/UTM" "6513870" "16Feb2009" "0:00:00" "eth0.70" "CP_FW2_01" "Log" "Drop" "46851" "6883" "xxx.xxx.xxx.xxx" "CP_FW2" "udp" "22" "" "22- FW2_StartPolicy_16_05_2008" "" "" "VPN-1 Power/UTM" "6513876" "16Feb2009" "0:00:00" "eth0.99" "CP_FW6_01" "Log" "Drop" "57480" "48939" "xxx.xxx.xxx.xxx" "NAT_noc_AS" "tcp" "94" "" "95- FW6_Policy_12_11_2008" "" "" "VPN-1 Power/UTM" "6513877" "16Feb2009" "0: 00:00" "eth1.399" "CP_FW6_01" "Log" "Accept" "http" "31305" "test. domain.com" "xxx.xxx.xxx.xxx" "tcp" "78" "" "78-FW6_Policy_12_11_2008" "" "service_id: http" "VPN-1 Power/UTM" "6513878" "16Feb2009" "0:00:00" "eth1.399" "CP_FW6_01" "Log" "Accept" "http" "1172" "test.domain.com" "xxx.xxx.xxx.xxx" "tcp" "76" "" "76-FW6_Policy_12_11_2008" "" "service_id: http" "VPN-1 Power/UTM" "6513879" "16Feb2009" "0:00:00" "eth0.99" "CP_FW6_01" "Log" "Drop" "57480" "56573" "xxx.xxx.xxx.xxx" "NAT_noc_AS" "tcp" "94" "" "95-FW6_Policy_12_11_2008" "" "" "VPN-1 Power/UTM" "6513880" "16Feb2009" "0:00:00" "eth1.399" "CP_FW6_01" "Log" "Drop" "http" "TCP_4239" "xxx.xxx.xxx.xxx" "xxx.xxx.xxx.xxx" "tcp" "94" "" "95-FW6_Policy_12_11_2008" "" "" "VPN-1 Power/UTM" "6513881" "16Feb2009" "0:00:01" "eth0.99" "CP_FW6_01" "Log" "Drop" "57480" "10018" "xxx.xxx.xxx.xxx" "NAT_noc_AS" "udp" "94" "" "95- FW6_Policy_12_11_2008" "" "" "VPN-1 Power/UTM" "6513883" "16Feb2009" "0: 00:00" "eth1.55" "CP_FW1_01" "Log" "Accept" "http" "52860" "xxx.xxx.xxx. xxx" "xxx.xxx.xxx.xxx" "tcp" "39" "" "39-FW1_StartPolicy_16_05_2008" "" "service_id: http" "VPN-1 Power/UTM" "6513884" "16Feb2009" "0:00:02" "eth1.55" "CP_FW1_01" "Log" "Accept" "http" "4922" "test.domain.com" "xxx.xxx.xxx.xxx" "tcp" "39" "" "39-FW1_StartPolicy_16_05_2008" "" "service_id: http" "VPN-1 Power/UTM" "6513885" "16Feb2009" "0:00:00" "eth0.18" "CP_FW5_01" "Log" "Drop" "13236" "16434" "xxx.xxx.xxx.xxx" "NAT_management" "udp" "24" "" "24-FW5_Startup_20_05_2008" "" "" "VPN-1 Power/UTM" "6513886" "16Feb2009" "0:00:00" "eth0.18" "CP_FW5_01" "Log" "Drop" "13236" "60337" "xxx.xxx.xxx.xxx" "NAT_management" "udp" "24" "" "24-FW5_Startup_20_05_2008" "" "" "VPN-1 Power/UTM" "6513887" "16Feb2009" "0:00:02" "eth0.18" "CP_FW5_01" "Log" "Drop" "11445" "33257" "xxx.xxx.xxx.xxx" "NAT_management" "udp" "24" "" "24- FW5_Startup_20_05_2008" "" "" "VPN-1 Power/UTM" this is the result of export to text from checkpoint I have also the possibility to use the binary file format but I think that those are unreadable from prelude-lml thanks in advance Attiva Tiscali Tutto Incluso: telefoni e navighi senza limiti A SOLI €10 AL MESE FINO ALL’ESTATE. Attiva entro il 19/02/09! http://abbonati.tiscali.it/promo/tuttoincluso/ _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user