1+ len(results) == 3
2+ results["s00-raw"]["crowdsecurity/unifi-logs"][0].Success == true
3+ results["s00-raw"]["crowdsecurity/unifi-logs"][0].Evt.Parsed["logsource"] == "syslog"
4+ results["s00-raw"]["crowdsecurity/unifi-logs"][0].Evt.Parsed["timestamp"] == "Jun 13 23:29:15"
5+ results["s00-raw"]["crowdsecurity/unifi-logs"][0].Evt.Meta["machine"] == "UDMP-DTC"
6+ results["s00-raw"]["crowdsecurity/unifi-logs"][1].Success == true
7+ results["s00-raw"]["crowdsecurity/unifi-logs"][1].Evt.Parsed["logsource"] == "syslog"
8+ results["s00-raw"]["crowdsecurity/unifi-logs"][1].Evt.Parsed["timestamp"] == "Feb 8 18:19:31"
9+ results["s00-raw"]["crowdsecurity/unifi-logs"][1].Evt.Meta["machine"] == "Unifi-Dream-Machine"
10+ results["s01-parse"]["PintjesB/unifi-logs"][0].Success == true
11+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["action"] == "D"
12+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["dst_ip"] == "192.168.1.25"
13+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["dst_port"] == "54329"
14+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["dst_zone"] == "LOCAL"
15+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["fw_descr"] == "[WAN_LOCAL]Block All Traffic"
16+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["if_in"] == "eth8"
17+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["logsource"] == "syslog"
18+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["mac"] == "74:ac:b9:1c:62:e5:00:17:10:2b:31:a9:08:00"
19+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["proto"] == "UDP"
20+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["remainder"] == "LEN=102 MARK=1a0000"
21+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["rule_id"] == "2147483647"
22+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["skip2"] == "122 TOS=00 PREC=0x00 TTL=49 ID=45366 DF"
23+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["source_ip"] == "3.3.3.3"
24+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["src_port"] == "38451"
25+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Parsed["timestamp"] == "Jun 13 23:29:15"
26+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Meta["log_type"] == "firewall_block_rule_hit"
27+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Meta["machine"] == "UDMP-DTC"
28+ results["s01-parse"]["PintjesB/unifi-logs"][0].Evt.Meta["source_ip"] == "3.3.3.3"
29+ results["s01-parse"]["PintjesB/unifi-logs"][1].Success == true
30+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["action"] == "D"
31+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["dst_ip"] == "10.10.10.10"
32+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["dst_port"] == "29552"
33+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["dst_zone"] == "LOCAL"
34+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["fw_descr"] == "[WAN_LOCAL]Drop All Other Traf"
35+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["if_in"] == "eth4"
36+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["logsource"] == "syslog"
37+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["mac"] == "fake-mac-address"
38+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["proto"] == "TCP"
39+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["remainder"] == "SEQ=2451790175 ACK=0 WINDOW=1024 SYN URGP=0 MARK=1a0000"
40+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["rule_id"] == "2147483647"
41+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["skip2"] == "40 TOS=00 PREC=0x00 TTL=239 ID=13706"
42+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["source_ip"] == "72.60.20.10"
43+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["src_port"] == "45584"
44+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Parsed["timestamp"] == "Feb 8 18:19:31"
45+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Meta["log_type"] == "firewall_block_rule_hit"
46+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Meta["machine"] == "Unifi-Dream-Machine"
47+ results["s01-parse"]["PintjesB/unifi-logs"][1].Evt.Meta["source_ip"] == "72.60.20.10"
0 commit comments