diff --git a/etc/decoder.xml b/etc/decoder.xml index 768f7d4f0..8ca3dc710 100755 --- a/etc/decoder.xml +++ b/etc/decoder.xml @@ -1691,6 +1691,27 @@ Jan 8 19:32:41 tp.lan dropbear[15165]: Pubkey auth succeeded for 'root' with ke url, srcip, id + + + + windows-date-format + web-log + true + ^\d+.\d+.\d+.\d+ GET |^\d+.\d+.\d+.\d+ POST + (\S+ \S*) \.* (\d+.\d+.\d+.\d+) \S*\.* (\d\d\d) \S+ \S+ \S+ + url,srcip,id + +