Community discussions

 
plisken
Forum Guru
Forum Guru
Topic Author
Posts: 2409
Joined: Sun May 15, 2011 12:24 am
Location: Belgium
Contact:

Email-script if a certain DSTNAT is used

Wed Jul 31, 2019 12:01 pm

I'd like to make a script.
If someone wants to log in via a DSTNAT rule
an email is sent to me.
I have created and logged the DSTNAT rule

The log looks like this

firewall,info DSTNAT-RULE dstnat: in:sfp-sfpplus1_WAN out:(unknown 0), src-mac xx:xx:xx:xx:xx:xx, proto TCP (SYN), 111.111.111.111:2019->10.10.10.10:10089, len 52
Can someone help me if the DSTNAT rule is used that I receive an email?
 
User avatar
cdiedrich
Forum Veteran
Forum Veteran
Posts: 899
Joined: Thu Feb 13, 2014 2:03 pm
Location: Basel, Switzerland // Bremen, Germany
Contact:

Re: Email-script if a certain DSTNAT is used

Wed Jul 31, 2019 1:04 pm

You might get lucky with this log parser script.
If you have more than a handful of equipment, it might be worth considering collecting all logs centrally. We're running Graylog to collect the logs from ~200 devices and setting up alerts in Graylog is really easy.

-Chris
Christopher Diedrich
MTCNA, MTCUME, MTCWE
Basel, Switzerland
Bremen, Germany

There are 10 types of people: Those who understand binary and those who don't.
There are two types of people: Those who can extrapolate from incomplete data

Who is online

Users browsing this forum: No registered users and 8 guests