@@ -3,23 +3,27 @@ len(results["s00-raw"]["crowdsecurity/non-syslog"]) == 4
33results["s00-raw"]["crowdsecurity/non-syslog"][0].Success == true
44results["s00-raw"]["crowdsecurity/non-syslog"][0].Evt.Parsed["message"] == "2023-04-23 21:53:37.311 -05:00 [WRN] Failed login attempt, 2FA invalid. 207.96.38.253"
55results["s00-raw"]["crowdsecurity/non-syslog"][0].Evt.Parsed["program"] == "bitwarden"
6- results["s00-raw"]["crowdsecurity/non-syslog"][0].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
6+ basename( results["s00-raw"]["crowdsecurity/non-syslog"][0].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
77results["s00-raw"]["crowdsecurity/non-syslog"][0].Evt.Meta["datasource_type"] == "file"
8+ results["s00-raw"]["crowdsecurity/non-syslog"][0].Evt.Whitelisted == false
89results["s00-raw"]["crowdsecurity/non-syslog"][1].Success == true
910results["s00-raw"]["crowdsecurity/non-syslog"][1].Evt.Parsed["message"] == "2023-04-23 21:53:54.706 -05:00 [ERR] Request to https://push.bitwarden.com/push/register is unsuccessful with status of \"BadRequest\"-Bad Request"
1011results["s00-raw"]["crowdsecurity/non-syslog"][1].Evt.Parsed["program"] == "bitwarden"
11- results["s00-raw"]["crowdsecurity/non-syslog"][1].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
12+ basename( results["s00-raw"]["crowdsecurity/non-syslog"][1].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
1213results["s00-raw"]["crowdsecurity/non-syslog"][1].Evt.Meta["datasource_type"] == "file"
14+ results["s00-raw"]["crowdsecurity/non-syslog"][1].Evt.Whitelisted == false
1315results["s00-raw"]["crowdsecurity/non-syslog"][2].Success == true
1416results["s00-raw"]["crowdsecurity/non-syslog"][2].Evt.Parsed["message"] == "2023-04-24 13:06:35.295 -05:00 [WRN] Failed login attempt. 207.96.38.253"
1517results["s00-raw"]["crowdsecurity/non-syslog"][2].Evt.Parsed["program"] == "bitwarden"
16- results["s00-raw"]["crowdsecurity/non-syslog"][2].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
18+ basename( results["s00-raw"]["crowdsecurity/non-syslog"][2].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
1719results["s00-raw"]["crowdsecurity/non-syslog"][2].Evt.Meta["datasource_type"] == "file"
20+ results["s00-raw"]["crowdsecurity/non-syslog"][2].Evt.Whitelisted == false
1821results["s00-raw"]["crowdsecurity/non-syslog"][3].Success == true
19- results["s00-raw"]["crowdsecurity/non-syslog"][3].Evt.Parsed["program"] == "bitwarden"
2022results["s00-raw"]["crowdsecurity/non-syslog"][3].Evt.Parsed["message"] == "2023-04-24 16:10:32.219 -05:00 [INF] Identity started."
21- results["s00-raw"]["crowdsecurity/non-syslog"][3].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
23+ results["s00-raw"]["crowdsecurity/non-syslog"][3].Evt.Parsed["program"] == "bitwarden"
24+ basename(results["s00-raw"]["crowdsecurity/non-syslog"][3].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
2225results["s00-raw"]["crowdsecurity/non-syslog"][3].Evt.Meta["datasource_type"] == "file"
26+ results["s00-raw"]["crowdsecurity/non-syslog"][3].Evt.Whitelisted == false
2327len(results["s00-raw"]["crowdsecurity/syslog-logs"]) == 4
2428results["s00-raw"]["crowdsecurity/syslog-logs"][0].Success == false
2529results["s00-raw"]["crowdsecurity/syslog-logs"][1].Success == false
@@ -35,26 +39,28 @@ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Parsed["message
3539results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Parsed["program"] == "bitwarden"
3640results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Parsed["source_ip"] == "207.96.38.253"
3741results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Parsed["timestamp"] == "2023-04-23 21:53:37.311"
42+ basename(results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
43+ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["datasource_type"] == "file"
44+ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["log_type"] == "bitwarden_failed_auth"
3845results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["service"] == "bitwarden"
3946results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["source_ip"] == "207.96.38.253"
40- results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
41- results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["datasource_type"] == "file"
42- results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Meta["log_type"] == "bitwarden_failed_auth_2fa"
47+ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][0].Evt.Whitelisted == false
4348results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][1].Success == false
4449results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Success == true
45- results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["program"] == "bitwarden"
46- results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["source_ip"] == "207.96.38.253"
47- results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["timestamp"] == "2023-04-24 13:06:35.295"
4850results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["exim_day"] == "24"
4951results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["exim_month"] == "04"
5052results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["exim_time"] == "13:06:35.295"
5153results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["exim_year"] == "2023"
5254results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["message"] == "2023-04-24 13:06:35.295 -05:00 [WRN] Failed login attempt. 207.96.38.253"
53- results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
55+ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["program"] == "bitwarden"
56+ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["source_ip"] == "207.96.38.253"
57+ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Parsed["timestamp"] == "2023-04-24 13:06:35.295"
58+ basename(results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
5459results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Meta["datasource_type"] == "file"
5560results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Meta["log_type"] == "bitwarden_failed_auth"
5661results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Meta["service"] == "bitwarden"
5762results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Meta["source_ip"] == "207.96.38.253"
63+ results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][2].Evt.Whitelisted == false
5864results["s01-parse"]["MariuszKociubinski/bitwarden-logs"][3].Success == false
5965len(results["s02-enrich"]["crowdsecurity/dateparse-enrich"]) == 2
6066results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Success == true
@@ -66,27 +72,29 @@ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["message"]
6672results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["program"] == "bitwarden"
6773results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["source_ip"] == "207.96.38.253"
6874results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Parsed["timestamp"] == "2023-04-23 21:53:37.311"
69- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
75+ basename( results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
7076results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["datasource_type"] == "file"
71- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["log_type"] == "bitwarden_failed_auth_2fa "
77+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["log_type"] == "bitwarden_failed_auth "
7278results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["service"] == "bitwarden"
7379results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["source_ip"] == "207.96.38.253"
7480results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Meta["timestamp"] == "2023-04-23T21:53:37.311Z"
7581results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Enriched["MarshaledTime"] == "2023-04-23T21:53:37.311Z"
82+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][0].Evt.Whitelisted == false
7683results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Success == true
77- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["message"] == "2023-04-24 13:06:35.295 -05:00 [WRN] Failed login attempt. 207.96.38.253"
78- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["program"] == "bitwarden"
79- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["source_ip"] == "207.96.38.253"
80- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["timestamp"] == "2023-04-24 13:06:35.295"
8184results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["exim_day"] == "24"
8285results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["exim_month"] == "04"
8386results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["exim_time"] == "13:06:35.295"
8487results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["exim_year"] == "2023"
85- results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["datasource_path"] == "bitwarden-logs.log"
88+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["message"] == "2023-04-24 13:06:35.295 -05:00 [WRN] Failed login attempt. 207.96.38.253"
89+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["program"] == "bitwarden"
90+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["source_ip"] == "207.96.38.253"
91+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Parsed["timestamp"] == "2023-04-24 13:06:35.295"
92+ basename(results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["datasource_path"]) == "bitwarden-logs.log"
8693results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["datasource_type"] == "file"
8794results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["log_type"] == "bitwarden_failed_auth"
8895results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["service"] == "bitwarden"
8996results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["source_ip"] == "207.96.38.253"
9097results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Meta["timestamp"] == "2023-04-24T13:06:35.295Z"
9198results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Enriched["MarshaledTime"] == "2023-04-24T13:06:35.295Z"
92- len(results["success"][""]) == 0
99+ results["s02-enrich"]["crowdsecurity/dateparse-enrich"][1].Evt.Whitelisted == false
100+ len(results["success"][""]) == 0
0 commit comments