Ā Ā <field name="dst_ip" type="pcre2">^(?!(10|127|169\.254|192\.168|172\.(2[0-9]|1[6-9]|3[0-1])|(25[6-9]|2[6-9][0-9]|[3-9][0-9][0-9]|99[1-9]))\.)[0-9]{1,3}(\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)){3}$</field>
Ā Ā <description>Detect external IP-Connections $(src_ip) to $(dst_ip) from $(dst_country)</description>
**Messages:
Ā Ā INFO: (7202): Session initialized with token 'b2ce7850'
**Phase 1: Completed pre-decoding.
Ā Ā full event: 'device_name="SFW" timestamp="2024-09-30T09:34:45+0200" device_model="XGS4300" device_serial_id="XXXXXXXX" log_id="010102600002" log_type="Firewall" log_component="Firewall Rule" log_subtype="Denied" log_version=1 severity="Information" fw_rule_id="91" fw_rule_name="Drop All" fw_rule_section="Local rule" nat_rule_id="3" nat_rule_name="default MASQ" fw_rule_type="USER" web_policy_id=2 ether_type="IPv4 (0x0800)" out_interface="Port2" src_ip="12.32.213.1" src_country="DEU" dst_ip="123.32.12.1" dst_country="USA" protocol="TCP" src_port=49708 dst_port=443 hb_status="No Heartbeat" app_resolved_by="Signature" app_is_cloud="FALSE" qualifier="New" out_display_interface="External WAN" log_occurrence="1"'
**Phase 2: Completed decoding.
Ā Ā name: 'sophos-fw'
Ā Ā app_is_cloud: 'FALSE'
Ā Ā app_resolved_by: 'Signature'
Ā Ā device_model: 'XXXXXXXXXXX'
Ā Ā device_serial_id: 'XXXXXXXXXXXX'
Ā Ā dst_country: 'USA'
Ā Ā dst_ip: '123.32.12.1'
Ā Ā fw_rule_id: '91'
Ā Ā log_id: '010102600002'
Ā Ā log_subtype: 'Denied'
Ā Ā log_type: 'Firewall'
Ā Ā protocol: 'TCP'
Ā Ā qualifier: 'New'
Ā Ā severity: 'Information'
Ā Ā src_country: 'DEU'
Ā Ā src_ip: '12.32.213.1'
Ā Ā timestamp: '2024-09-30T09:34:45+0200'
**Phase 3: Completed filtering (rules).
Ā Ā id: '700032'
Ā Ā level: '0'
Ā Ā description: 'Detect external IP-Connections 12.32.213.1 to 123.32.12.1 from USA'
Ā Ā groups: '["sophos-fw"]'
Ā Ā firedtimes: '1'
Ā Ā mail: 'false'