Graylog2 / Graylog2/illuminate-documentation
Add schema fields for Barracuda Web Proxies
- Dominant language
- HTML
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
Customer request per HS-1473167439
**Please describe what you are requesting**
The customer uses Baracuda Proxies, and a few fields are missing in the schema. Here is a documentation of the Logs from baracuda:
[https://campus.barracuda.com/product/websecuritygateway/doc/6160435/syslog-and-the-barracuda-web-security-gateway/?lang=2AJYS](https://campus.barracuda.com/product/websecuritygateway/doc/6160435/syslog-and-the-barracuda-web-security-gateway/?lang=2AJYS)
**Describe what change you are proposing**
http_content_category - matches the field of Matched Category of that
documentation
http_content_category_reason - matches the field of "Matched Part" for
that category
http_referrer_category_Matechedcategory - quite self explaining
http_referrer_domain - quite self explaining
http_referrer_url - quite self explaining
threat_name - here the value of "Spy ID"
threat_action - here the value of "Spy Type"
**_From customer:_**
"threat_name" is a field we would use for the Field "Spy ID" from Barracuda Security Gateways. It contains the name of spyware if something is blocked because of said spyware.
We want to use the "threat_action" for the "Spy Type", also from Barracuda Security Gateways. In this case it contains numbers from one to six, depending on what predefined action the system took. But I see it as a more general field, that's supposed to contain the action a system took to prevent/remediate some threat(usually as a text-field).
**Describe the log source**
Barracuda Web Security Gateway: [https://www.barracuda.com/products/network-security/web-security-gateway/features](https://www.barracuda.com/products/network-security/web-security-gateway/features)
**Attach any sample logs or examples for details**
"How to parse" and example logs at: [https://campus.barracuda.com/product/websecuritygateway/doc/6160435/syslog-and-the-barracuda-web-security-gateway/](https://campus.barracuda.com/product/websecuritygateway/doc/6160435/syslog-and-the-barracuda-web-security-gateway/)
Contributor guide
Research direction
No repository files or tests are named. Start by reviewing the linked Barracuda Web Security Gateway syslog documentation and locating the repository's schema definitions for log fields; compare the requested fields and source values with existing conventions. Done means the supported schema contains the requested Barracuda fields with consistent names and mappings, with any relevant validation or documentation updated.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, networking, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100