Hello, to start the year nice - need to come back on an issue described below - which I seem to not have fixed completely …
I have the following situation:
- One of my Organisations I have only set with an AS number (all others I have their IP address ranges set).
- The parsing is matching the ASN number (shown with —export, example below), but misses the country code (not sure if relevant)
- The Organisation is not matched - therefore no email address seen in the below —export output.
- The ASN is not written to the DB
- When I add the IP address range to the organisation / AS in the DB, it matches completely - adds the country code and the organisation.
What am I missing (?)
Example data used:
Src IP address: 192.168.1.2
ASN: 65455
—
2014-01-01 00:34:37 UTC 192.168.1.2 asn="65455", asn2="", Category="openresolvers", Comment="", DstIP=" ", DstPort=" ", Malware="", OldCategory="openresolvers", SrcPort=" " 0 2014-01-02 10:29:39 UTC 2014-01-01 00:34:37 192.168.1.2 65455 openresolvers GB 2014-01-02 02:37:03 openresolvers ripencc GB 2684829
---
Note: the above is one line.
—
filter.preLineProcessor.classNames.0=se.sitic.megatron.filter.LineNumberFilter
filter.lineNumberFilter.excludeIntervals=1-1
# Skip file if same as previous file
general.fileAlreadyProcessedAction=skip
fileProcessor.classNames.0=se.sitic.megatron.fileprocessor.DiffProcessor
# Filter: Entries are decorated *before* filter.
#filter.preStorage.classNames.0=se.sitic.megatron.filter.OrganizationOrCountryCodeFilter
filter.organizationFilter.matchIpAddress=true
#filter.organizationFilter.matchHostname=true
filter.organizationFilter.matchAsn=true
#filter.countryCodeFilter.includeCountryCodes=