<decoder name="pix-fw14"> <parent>pix-2</parent> <type>firewall</type> <prematch offset="after_parent">^3-305006</prematch> <regex offset="after_parent">(\S+): </regex> <regex>(\w+) translation creation failed for (\w+) src (\S+):(\S+)\s+dst (\S+):(\S+)\s+\(type (\d+), code (\d+)\)|</regex> <regex>(\S+): (\w+) translation creation failed for (\w+) src (\S+):(\S+)/(\d+) dst (\S+):(\S+)/(\d+)</regex> <order>id, type, protocol, srcint, srcip, srcport, dstint, dstip ,dstport, icmptype, icmpcode</order></decoder>%ASA-3-305006: regular translation creation failed for icmp src VoIP:192.168.5.74 dst outside:1.1.1.1 (type 3, code 3)%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)%ASA-3-305006: portmap translation creation failed for tcp src inside-192.168.5.x:192.168.5.2/342 dst outside:1.1.1.1/443 %ASA-3-305006: portmap translation creation failed for tcp src inside-192.168.5.x:192.168.5.2/342 dst outside:1.1.1.1/443
**Phase 1: Completed pre-decoding. full event: '%ASA-3-305006: portmap translation creation failed for tcp src inside-192.168.5.x:192.168.5.2/342 dst outside:1.1.1.1/443' timestamp: '(null)' hostname: 'wazuh' program_name: '(null)' log: '%ASA-3-305006: portmap translation creation failed for tcp src inside-192.168.5.x:192.168.5.2/342 dst outside:1.1.1.1/443'
**Phase 2: Completed decoding. decoder: 'pix-2' id: '3-305006' type: 'portmap' protocol: 'tcp' srcint: 'inside-192.168.5.x' srcip: '192.168.5.2' srcport: '342' dstint: 'outside' dstip: '1.1.1.1' dstport: '443'
**Phase 3: Completed filtering (rules). Rule id: '4100' Level: '0' Description: 'Firewall rules grouped.'
%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)
**Phase 1: Completed pre-decoding. full event: '%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)' timestamp: '(null)' hostname: 'wazuh' program_name: '(null)' log: '%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)'
**Phase 2: Completed decoding. decoder: 'pix-2' id: '3-305006' type: 'regular' protocol: 'icmp' srcint: 'inside-192.168.5.x' srcip: '192.168.5.2' srcport: 'outside' dstint: '1.1.1.1' dstip: '3' dstport: '3'
**Phase 3: Completed filtering (rules). Rule id: '4100' Level: '0' Description: 'Firewall rules grouped.'
<decoder name="pix-fw14"> <parent>pix-2</parent> <type>firewall</type> <prematch offset="after_parent">^3-305006</prematch> <regex offset="after_parent">(\S+): </regex> <regex>(\w+) translation creation failed for (\w+) src (\S+):(\S+)(\s+)dst (\S+):(\S+)(\s+)\(type (\d+), code (\d+)\)|</regex> <regex>(\S+): (\w+) translation creation failed for (\w+) src (\S+):(\S+)/(\d+) dst (\S+):(\S+)/(\d+)</regex> <order>id, type, protocol, srcint, srcip, srcport, dstint, dstip ,dstport, icmptype, icmpcode</order></decoder>
%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)
**Phase 1: Completed pre-decoding. full event: '%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)' timestamp: '(null)' hostname: 'wazuh' program_name: '(null)' log: '%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)'
**Phase 2: Completed decoding. decoder: 'pix-2'
**Phase 3: Completed filtering (rules). Rule id: '4100' Level: '0' Description: 'Firewall rules grouped.'
<decoder name="pix-fw14"> <parent>pix-2</parent> <type>firewall</type>
<regex offset="after_parent">(\S+): (\w+) translation creation failed for (\w+) src (\S+):(\S+)\s+dst (\S+):(\S+)\s+\(type (\d+), code (\d+)\)</regex>
<order>id, type, protocol, srcint, srcip, srcport, dstint, dstip ,dstport, icmptype, icmpcode</order> </decoder>
<decoder name="pix-fw14"> <parent>pix-2</parent> <type>firewall</type>
<regex offset="after_parent">(\S+): </regex> <regex>(\S+): (\w+) translation creation failed for (\w+) src (\S+):(\S+)/(\d+) dst (\S+):(\S+)/(\d+)</regex>
<order>id, type, protocol, srcint, srcip, srcport, dstint, dstip ,dstport, icmptype, icmpcode</order> </decoder>
%ASA-3-305006: regular translation creation failed for icmp src inside-192.168.5.x:192.168.5.2 dst outside:1.1.1.1 (type 3, code 3)
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+un...@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/6fea3d6a-1377-4113-9936-33114a2b3ce7%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
