Welcome back to the summary course in building. You're in for a sec lap. I'm your host and instructor Kevin Hernandez.
Blast lesson. Well integrated pf sense locks into curator and created it as a universal GSM luck source
in today's lesson actually gonna start creating custom properties for RPF since locks we thin curator.
Now let's get started.
Last realists off. We basically integrated pf since logs through. Curator We had the status
Even though we incur incorporated these logs
you have to do it manually through the universal log D s. Um,
that's a scene on the screen
now, even though we integrated these one of the issues is that it is not properly formatted. The reason we have to create either a universal
the ascend four p of sense I know scramble of words, right? Or we have to create custom variables. Now, let's go ahead and posit We're right here.
So we pause to capture from curator hitting the pause button on the top right corner.
And now we're gonna open a P of sense event such as this one.
you have information here,
but not much to do. Now,
that's a mention. In the last videos, we can create
a new GSM right, or we can actually extract barrels from here.
Let's go ahead and show you the extract properties or create custom Bibles for this option. 1st 2 status.
let's go down here to locks again.
And here are the system looks now, obviously, you deaf system. And we also have the far wall. She's the ones we're looking at, right? So one good thing we're gonna do here is we're actually gonna take a swan screen shot of this
and then compare it to what we have here.
I also do a side by side. If you like
that, you come here,
shrink this a little, and then come here.
Put them side by side.
It's up to preference.
So here, Right, you have the date or time, right?
Have the rule. Are pretty sure that's what it iss. And then you can see
her. Cyril values right.
Several values, right. Interfaces match block. Right.
if I expended a little
all right, you can actually see some of this information.
However, it's not in the second order. So you gotta be aware of that
when trying to match one toe, One the information. Okay,
and see the other one.
That one thing you can do,
you can right click here
filter on lockers is P f sense unless and the last 15 minutes.
And there we go. We have a lot more data to play with.
1 20 So let's try to find
thes event in there,
Once I went to Dynamic be a mentor. A normal view was able to find 1 2050 to 1 52 15
Right here. The port for 4193
Whoops. Sorry. I'm sure I did there.
I'm gonna go ahead and search for it in 44193 Right.
And you have the porter here.
You can see the 32 80. Here. You see the 30 to 60 m sign right here, and you can could get a general idea. Now, why this one? And this is what we really wanted to do.
So let's go ahead and copy
and Alice to extract property.
That's why for it to load
I want to do is create custom barrels for these, it's to show you how we can do a couple of, um regarding curator. Right. So we're going to extraction maze, right? Test feel it's where are pale is gonna be. In this case, you can see actually pasted it in here, so I don't have to do too much. Now here comes the exact new property. This case, we could
here. Right source. I p just 1 20
maybe actually at a p f sense. And the reason I like to do p of scent source I p
Because that way, if you're trying to use your safety for something else, you don't. All right? You're certainly be for everything else. Okay. And for me to say, this is the source i p
Let's scroll down a little. I'm gonna actually
creases sign of this. A little
fits. You guess It's a universal descend lobsters. You can actually attach it to be a sense itself. Even need. We can actually jump into that later on. But right now I'm gonna show you how to you simple rat Jax to read this data. Now, if you taking my course and Reddick, you already should be a little bit familiarized with this.
Otherwise, I'm gonna do
a little quick and true about it. Not too complex right now. You can see you do have to bracket. Now, if you want to get the date,
we can actually start from left to right, or we can actually start with the i p. I got ready stated. So
the problem is, we start here Is that when you have to create this portion under Rogic's for all of these,
right and it's a lot of information, to be honest with you.
So what you can do is we can start instead around
And the reason I say it's we can start around here is because it's not that hard or we can actually use this colon.
The reason I mentioned a Collins because it is the last colon there is, and therefore it shouldn't be that hard to play around with. So let's start with that colon right and it's been detected, followed by
let's say a little bit bigger now. I can see So the colon, Right. And you can see there's one,
three different Collins. Now, the difference is you see carefully here.
This one has a space afterwards. So we're gonna use that
to Reg IX scenario. We're starting right now. There could be a dot or not, um, you know, digit or not. So in this case, what I'm gonna do is we're gonna create a
You're gonna say cute for cannot be there. Right? And they were gonna do a coma.
What a wild card I can or cannot be. They're actually going to repeat this several times
to everyone. And then here, for example,
You have digits, right? So it's a slash d plus. So you cover all those numbers, then you do another coma. In this case, it's a word,
right? Causes the interface so you could do slash
doubly pull us right. You're actually going to repeat this? Same one several times now,
it's gonna be a little bit long,
but it's gonna be okay.
And then you can say
Molly or no valley slash Did it? Plus
teach it? Plus, they're gonna keep repeating these again
until we get to the point where we want to reach right slash
You can see once we go to the d S m. It might be a little bit or a lot cleaner,
you'll be happy then
coma. I slashed w plus for a TCP
together coma, and he usually actually gonna have to source i p.
here's where we do the capture. Now, before you do the capture group, one of the things I'm gonna recommend, it's for a ride, the whole
being up to maybe hear the destination port. Okay.
And the reason I say that is
you can then use the same rad jacks for everything you're gonna do instead of having to rewrite everything again and miss up because you forgot where to capture proper capture groups is okay Now, these seems like a good place to take a short break. See you soon