From bf16910799d2e075670441540a206227832e3829 Mon Sep 17 00:00:00 2001 From: iasdeoupxe <39667843+iasdeoupxe@users.noreply.github.com> Date: Sat, 15 Dec 2018 13:45:46 +0100 Subject: [PATCH 1/4] Postfix decoder: Making ending doubled dot optional --- decoders/0220-postfix_decoders.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/decoders/0220-postfix_decoders.xml b/decoders/0220-postfix_decoders.xml index 12b804fcb..8326ea64d 100644 --- a/decoders/0220-postfix_decoders.xml +++ b/decoders/0220-postfix_decoders.xml @@ -46,7 +46,7 @@ true postfix ^warning: - ^warning: (\S+):|warning: Illegal address syntax from unknown[(\S+)]|warning: hostname \S+ does not resolve to address (\S+): + ^warning: (\S+):|warning: Illegal address syntax from unknown[(\S+)]|warning: hostname \S+ does not resolve to address (\S+) srcip From 465c34ede6d37cf571e44f09651a2bc5cce3e706 Mon Sep 17 00:00:00 2001 From: iasdeoupxe <39667843+iasdeoupxe@users.noreply.github.com> Date: Fri, 23 Aug 2019 09:51:29 +0200 Subject: [PATCH 2/4] Updated regex to make the ending doubled dot optional while keeping support for IPv6 IP addresses. Updated / added log examples. --- decoders/0220-postfix_decoders.xml | 20 +++++++++++--------- 1 file changed, 11 insertions(+), 9 deletions(-) diff --git a/decoders/0220-postfix_decoders.xml b/decoders/0220-postfix_decoders.xml index 8326ea64d..9e0123616 100644 --- a/decoders/0220-postfix_decoders.xml +++ b/decoders/0220-postfix_decoders.xml @@ -11,16 +11,18 @@ @@ -46,7 +48,7 @@ true postfix ^warning: - ^warning: (\S+):|warning: Illegal address syntax from unknown[(\S+)]|warning: hostname \S+ does not resolve to address (\S+) + ^warning: (\S+):|warning: Illegal address syntax from unknown[(\S+)]|warning: hostname \S+ does not resolve to address (\S+): |warning: hostname \S+ does not resolve to address (\S+) srcip From ac9fbcc21ae3bc2961c85d54998fc2f8c4ce3e07 Mon Sep 17 00:00:00 2001 From: iasdeoupxe <39667843+iasdeoupxe@users.noreply.github.com> Date: Fri, 23 Aug 2019 09:58:31 +0200 Subject: [PATCH 3/4] Use an on-line example log entry. --- decoders/0220-postfix_decoders.xml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/decoders/0220-postfix_decoders.xml b/decoders/0220-postfix_decoders.xml index 9e0123616..a91011068 100644 --- a/decoders/0220-postfix_decoders.xml +++ b/decoders/0220-postfix_decoders.xml @@ -11,9 +11,7 @@