Professional Documents
Culture Documents
Sample Configurasi Sso
Sample Configurasi Sso
Slf4jLoggingAudi
tTrailManager] - Audit trail record BEGIN
=============================================================
WHO: [username: atikah.amalina]
WHAT: TGT-34940-69tJ3rxAhT4zKp3UD0bsag4k3H5Mc7oanwzdoHZbRKmarbzcfv-sso.ui.ac.id
ACTION: TICKET_GRANTING_TICKET_CREATED
APPLICATION: CAS
WHEN: Wed Nov 25 19:58:56 WIB 2015
CLIENT IP ADDRESS: 36.84.70.202
SERVER IP ADDRESS: 127.0.0.1
=============================================================
2015-11-25 19:58:56,958 INFO [org.jasig.cas.CentralAuthenticationServiceImpl] Granted service ticket [ST-53764-tbPXhFceimkOCcnUrvHo-sso.ui.ac.id] for service
[http://remote-lib.ui.ac.id/login] for user [atikah.amalina]
############################################################################
Pattern grok 1:
%{TIMESTAMP_ISO8601:time} %{WORD:event_method} \[%{NOTSPACE:package_service}\] %{GREEDYDATA:event_status}\n([=]*)\nWHO: \[username\: %{USERNAME:who}\]\nWHAT:
%{NOTSPACE:what}\nACTION: %{NOTSPACE:action}\nAPPLICATION: %{NOTSPACE:applicatio
n}\nWHEN: %{DATESTAMP_OTHER:when}\nCLIENT IP ADDRESS: %{IP:client_ip}\nSERVER IP
ADDRESS: %{IP:server_ip}\n([=]*)
support pattern grok 1:
TZ (?:[PMCEW][SDI]B|T[A]|UTC|)
add field grok 1:
event_type = request
remove field grok 1:
YEAR, MONTHNUM, MONTHDAY, HOUR, MINUTE, SECOND, ISO8601_TIMEZONE, DAY, MONTH, TI
ME, IPV6, IPV4
considered field grok 1:
TZ (timezone)
Pattern grok 2:
%{TIMESTAMP_ISO8601:time} %{WORD:event_method} \[%{NOTSPACE:service_package}\] %{GREEDYDATA:event_status} \[%{NOTSPACE:what}\] for service \[%{URI:service_add
ress}\] for user \[%{USERNAME:username}\]
add field grok 2:
event_type = response
remove field grok 2:
YEAR, MONTHNUM, MONTHDAY, HOUR, MINUTE, SECOND, ISO8601_TIMEZONE, URIPROTO, URIH
OST, IPORHOST, HOSTNAME, IP, IPV4, IPV6, port, URIPATHPARAM, URIPATH, URIPARAM
############################ Config FILE ###################################
input {
file {
path => "/var/log/messages.log"
codec => multiline {
pattern => "^%{TIMESTAMP_ISO8601}"