Skip to content

Instantly share code, notes, and snippets.

@ryanfaircloth
Created September 7, 2019 23:31
Show Gist options
  • Save ryanfaircloth/237f9e1b5f354afcf795f2928debb046 to your computer and use it in GitHub Desktop.
Save ryanfaircloth/237f9e1b5f354afcf795f2928debb046 to your computer and use it in GitHub Desktop.
#!/bin/bash
# Fortigate
# <111> Aug 17 00:00:00 fortigate date=2015-08-11 time=19:19:43 devname=fortigate-host devid=FG800C3912801080 logid=0004000017 type=traffic subtype=sniffer level=notice vd=root srcip=fe80::20c:29ff:fe77:20d4 srcintf="port3" dstip=ff02::1:ff77:20d4 dstintf="port3" sessionid=408903 proto=58 action=accept policyid=2 dstcountry="Reserved" srccountry="Reserved" trandisp=snat transip=:: transport=0 service="icmp6/131/0" duration=36 sentbyte=0 rcvdbyte=40 sentpkt=0 rcvdpkt=0 appid=16321 app="IPv6.ICMP" appcat="Network.Service" apprisk=elevated applist="sniffer-profile" appact=detected utmaction=allow countapp=1
echo
echo Sending Fortigate event:
echo
echo -e "<111> Aug 17 00:00:00 fortigate date=`date +%Y-%m-%d` time=`date +%H:%M:%S` devname=fortigate-host devid=FG800C3912801080 logid=0004000017 type=traffic subtype=sniffer level=notice vd=root srcip=fe80::20c:29ff:fe77:20d4 srcintf=\"port3\" dstip=ff02::1:ff77:20d4 dstintf=\"port3\" sessionid=408903 proto=58 action=accept policyid=2 dstcountry=\"Reserved\" srccountry=\"Reserved\" trandisp=snat transip=:: transport=0 service=\"icmp6/131/0\" duration=36 sentbyte=0 rcvdbyte=40 sentpkt=0 rcvdpkt=0 appid=16321 app=\"IPv6.ICMP\" appcat=\"Network.Service\" apprisk=elevated applist=\"sniffer-profile\" appact=detected utmaction=allow countapp=1"
echo -e "<111> Aug 17 00:00:00 fortigate date=`date +%Y-%m-%d` time=`date +%H:%M:%S` devname=fortigate-host devid=FG800C3912801080 logid=0004000017 type=traffic subtype=sniffer level=notice vd=root srcip=fe80::20c:29ff:fe77:20d4 srcintf=\"port3\" dstip=ff02::1:ff77:20d4 dstintf=\"port3\" sessionid=408903 proto=58 action=accept policyid=2 dstcountry=\"Reserved\" srccountry=\"Reserved\" trandisp=snat transip=:: transport=0 service=\"icmp6/131/0\" duration=36 sentbyte=0 rcvdbyte=40 sentpkt=0 rcvdpkt=0 appid=16321 app=\"IPv6.ICMP\" appcat=\"Network.Service\" apprisk=elevated applist=\"sniffer-profile\" appact=detected utmaction=allow countapp=1" | nc -w 1 sc4s.smg.aws 514
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment