#sourcetype for Sofrel S4W [sofrel:s4w] SHOULD_LINEMERGE=false KV_MODE = none EXTRACT-sofrel-s4w-generic = (?[A-Z][a-z]{2}\s+\d{1,2}\s+\d{1,2}:\d{1,2}:\d{1,2}) \S+ - (?.+) EXTRACT-sofrel-s4w-lost-mon-msg = (?Lost) (?monitoring messages) EXTRACT-sofrel-s4w-crt = ((?\S+) - )?(?Product|Root) (?certificate)( Authority)?( -)? (?Imminent expiration|expired|modified|not trusted) EXTRACT-sofrel-s4w-revoc-list = ((?\S+) - )?(?Revocation list) (?update failure|modified|removed|ignored) EXTRACT-sofrel-s4w-crt-key-mismatch = (?Product) (?certificate) and key doesn’t match EXTRACT-sofrel-s4w-auth-not-trusted = not trusted by (?.+) EXTRACT-sofrel-s4w-sys-conn-ref = (?System connection) (?refused) by (?[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3})? ?(CN=(?.+))? EXTRACT-sofrel-s4w-refusal-crt = (?Refusal) \((?Expiration|Revocation|Future validity|Bad CN|Not trusted by the CA|Other)\) of the received (?certificate) of system \[(?[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}) CN=(?.+)\] EXTRACT-sofrel-s4w-mng-fault = (?Management fault) (?(dis)?appeared) EXTRACT-sofrel-s4w-dwn-conf = ((?\S+) - )?(?Download|Read) (?Configuration|Software) (?V[0-9\.]+) EXTRACT-sofrel-s4w-conf-refuse = New (?Configuration|Software) (?refused) by the product EXTRACT-sofrel-s4w-dwn = ((?\S+) - )?(?Download) (?User List|Options) EXTRACT-sofrel-s4w-user-modif = ((?\S+) - )?(?User) (?.+) (?created|deleted|updated) EXTRACT-sofrel-s4w-erase-arch = (?\S+) - (?Erase) (?archive) EXTRACT-sofrel-s4w-switch-mode = Switch on (?normal|degraded) mode EXTRACT-sofrel-s4w-fault = (?External alimentation|Battery|System) fault : (?OFF|ON) EXTRACT-sofrel-s4w-conn-fail-crt = (?System) (?connection failure) (?.+) \((?bad Common Name|revoked|not valid yet|expired|not trusted by the root Authority)\) EXTRACT-sofrel-s4w-conn-unk = (?System) (?connection unknown) (?[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}) EXTRACT-sofrel-s4w-conn-refuse = (?System) (?connection refused) by (?.+) (client|server) EXTRACT-sofrel-s4w-network-attack = (?Network) (?attack) \((?(SYN|PING) Flood)\) detected from IP (?[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}) EXTRACT-sofrel-s4w-server-state = Server (?NTP|DNS|SMTP) : (?N?OK) EXTRACT-sofrel-s4w-user-conn = ((?\S+) - )?(?Local|Remote) user (?connection)( (?failure))?(, (?user outside validity period))? EXTRACT-sofrel-s4w-user-unk = User unknown \(?(?[^\(\)\s]+)\)? - (?Local|Remote) (?connection) (?failure) EXTRACT-sofrel-s4w-badging-unk = (?Badging) .(?COM.). - (?unknown) badge N. ?(?.+) EXTRACT-sofrel-s4w-pass-chg = (?Password) change notification to Management : (?failure|success) EXTRACT-sofrel-s4w-mng-user-list = Management - (?User List) receipt (?failure) \((not managed)\) EXTRACT-sofrel-s4w-badging-id = (?Badging) .(?COM.). - (?Identification) .(?.*).