diff --git a/decoders/0170-nginx_decoders.xml b/decoders/0170-nginx_decoders.xml index b3c33255d..3b79ba86f 100644 --- a/decoders/0170-nginx_decoders.xml +++ b/decoders/0170-nginx_decoders.xml @@ -8,10 +8,12 @@ --> ^20\d\d/\d\d/\d\d \d\d:\d\d:\d\d [ @@ -29,6 +31,19 @@ Extract NAXSI WAF alert information https://github.com/nbs-system/naxsi/wiki/nax srcip,server,uri,learning,vers,total_processed,total_blocked,block,attack,score + + nginx-errorlog + user "\.+" + user "(\.+)" + dstuser + + + + nginx-errorlog + client: (\S+), + srcip + + nginx-errorlog , client: \S+, server: \S*, request: "\S+