Closes the parsing gap the README explicitly called out (no D-Link parsing, no ZTE ONU alarms) plus adds BDCOM GPON and expands Juniper coverage (DDoS, PSU/memory/ASIC hardware faults, LACP/BGP/SNMP, config commit). 58 new rules across 5 vendors, wired into Network Equipment Parsing's stage 0 ahead of the generic_critical_severity fallback. Where the same real-world event is reported by multiple vendors (dying_gasp, onu_offline, optical_low_power, cli_login/cli_logout, config_saved, interface_link_state, lag_state_change), rules share one event_type value so dashboards can aggregate across vendors, same normalization approach as accelppp_interface. Built directly from the user's CSV signature report, not from real device log samples - each rule's description says so explicitly. `when` conditions use plain substring/contains matching on the report's own pattern text to keep classification robust; regex field extraction is only added where the source format is unambiguous. Passed offline checks (JSON validity, every pipeline-referenced rule resolves to a file, all regex patterns compile). Live compilation against a running Graylog instance - which caught 2 real bugs during the dashboard/stream fixes earlier this session - could NOT be completed: the test container went unreachable mid-session. Re-run install-graylog.sh once it's back up to confirm these compile before relying on them.
5 lines
827 B
JSON
5 lines
827 B
JSON
{
|
|
"title": "bdcom_gpon_dying_gasp",
|
|
"description": "BDCOM GPON: ONU power loss (Dying Gasp) - gpon_bdcom.csv row 2. Shares the 'dying_gasp' event_type with bdcom_epon_dying_gasp and the ZTE dying-gasp rules for a cross-vendor view. Built from the provided report, not yet verified against real device output.",
|
|
"source": "rule \"bdcom_gpon_dying_gasp\"\nwhen\n contains(to_string($message.message), \"GPON-ONUDGI\") && contains(to_string($message.message), \"Dying Gasp\")\nthen\n set_field(\"vendor\", \"bdcom_gpon\");\n set_field(\"event_type\", \"dying_gasp\");\n set_field(\"severity_tag\", \"critical\");\n let m = regex(\"ONU (\\\\S+) Dying Gasp on GPON(\\\\S*)\", to_string($message.message), [\"onu\",\"iface\"]);\n set_field(\"onu_id\", m[\"onu\"]);\n set_field(\"gpon_interface\", m[\"iface\"]);\nend"
|
|
}
|