FW FW-FW-Security-Event FW-FW-Security-Log TIME GATEWAYIP DENY TIMESTAMP_FW APPLIANCENAME TYPE IDS_EVENT SIGNATURE PRIORITY TIMESTAMP_EPOCH HOST_MAC_SRC DIRECTION PROTOCOL HOST_IP_SRC PORT_SRC HOST_IP_DST PORT_DST MESSAGE FW-FW-Security-Event true 1 1495179161.921631238 FW01 security_event ids_alerted signature=1:39867:3 priority=3 timestamp=1495179160.951639 shost=F0:DE:F1:80:EE:2E direction=egress protocol=udp/ip src=192.168.10.29:63354 dst=192.168.1.204:53 message: INDICATOR-COMPROMISE Suspicious .tk dns query filter { grok { %{NUMBER:deny_action1} %{NUMBER:timestamp_cppm} %{WORD:appliancename} %{WORD:type} %{WORD:IDS_Event} signature=%{DATA:signature} priority=%{NUMBER:priority} %{DATA:timestamp} shost=%{DATA:host_mac_src} direction=%{DATA:direction} protocol=%{DATA:protocol} src=%{IP:host_ip_src}:%{DATA:port_src} dst=%{IP:host_ip_dst}:%{DATA:port_dst} message:%{GREEDYDATA:syslog_message}} }