crowdsec/config/patterns/tcpdump
Thibault bui Koechlin 2016167654 initial import
2020-05-15 11:39:16 +02:00

2 lines
163 B
Plaintext

TCPDUMP_OUTPUT %{GREEDYDATA:timestamp} IP %{IPORHOST:source_ip}\.%{INT:source_port} > %{IPORHOST:dest_ip}\.%{INT:dest_port}: Flags \[%{GREEDYDATA:tcpflags}\], seq