Welcome back to the savory course in building. You're in for a sec lap. I'm your host and instructor Kevin Hernandes.
Last listen, we created custom properties for P f sense within our curator environment in today's lesson to actually gonna take it a little step of of that and create a custom the of sense for P f sense itself.
Now let's get started.
Let's mention of her prior lesson.
Another option we have to our custom barrels were concerned. Property.
It's the d S M editor itself. However, before we go, then
let's go ahead and copy this. And now go to
scroll down a little.
The nearest is, um, editor.
You got a second for its load
and it's gonna surfer
you gonna take PF sounds. You can see there's nothing you can do is, for example, you can say universal.
Do you serve in any create new?
All right. You can call it p f sentence.
But when you select it
and here it will be basically the same thing. But it earlier regarding the variables,
the only big difference is that now we actually modify it here with the variables you see on the left side for a set of heading. Ah pf send destination. I pee wee just modified a field here. Assist Destination I p Okay, so
the payload week acquired and lock it in here. Now you can see the data that's been extracting down here in the bomb, and you can see it's pretty much empty because it's not properly
interacting. Are interpreting interpretative. What's being detected for destination eyepiece? It's not being so. Detectives, you're gonna override it, right? Are gonna go back to our no pad.
All right, we're gonna capture this, right? You're gonna paste it here.
Expression. There we go.
Actually, it is detecting a couple of them
up here and see the 1st 1 in Texas. A source, I p. That's most likely because we
had the brackets right there.
So let's delete this.
Let's go to the other one.
Now the search for this I believe you should be here.
It's not. We'll move around
because it's actually no, it's one less
right here. Sorry. It's hard to see the comas in the periods today.
I have allergies. It's seriously bad. It will be here. In there. That's the destination. I peek for mustering batter required.
It's actually dollar one Apologize, curator. And you can see the destination piece right here, right now. Now what we're gonna do is that same dame. I'm gonna do it for the
source. I p So let's scroll down
alphabetically. Order over. Right. And remember, the Rogic's itself was probably former for source I p. So all you have to do a dollar sign. One hit, okay? And if you scroll to the side, you could see the source. I p Now they're Reagan. You can see. Basically the hard part about this was building that rejects will be able
in their fire. Listen.
And now this is like a piece of cake moving forward. Now,
We want to capture the other ones.
You know what? Let's actually do the following. Sorry.
This open different windows either way. So the destination port we're going over there, right? That a swell projects I'm gonna search for does
parentheses right there.
I'm gonna Sorry. Parentheses.
Surfer it right there.
Mom and I search for the other one.
deleted there, Tex Charity. And let's move to deports
you remember, the 1st 1 is for the stores. The second was for a destination. We're in destination. So before we do anything, that's copy paste this since it's clean. Now
Understood. Destination port, Remember, in this case is we're building a Rat IX itself. We have to actually put the capture group this case We only have one. So we put one
You should have it in there now.
80 80 80 80. Perfect. And let's go toe sore sport
over rate. In this case, it traffics again. Paste it. This case, you already know it's this one,
There we go and capture one because we only have one heat. Okay. Now, for example, we're gonna search for action or event name, so let's go for
I'm gonna do 1 34 here so we can do, for example, bomb.
four digits. Let's say even though we do see three
bump and this actually put the parentheses
he k is even I d. And then it's not that most like like firewall rule. But you get an idea that we won't have to recreate the many things right.
And now the only thing we need is gonna have the date or time. That's Dellis reading it properly. Since it's going live, you have to reinvent the way over that one. But if you want to use the system time in case there's some latent see, you can actually capture that. And what I would do is ah from here, right.
Open the parenthesis here and then do all the red X up to here, which, if you remember it was, um, you know, actually, space w here. So colon flash D to slash space writing and captured her here before the space and that should be able to work.
let's look for one more thing in here,
which is the action, right?
We're not. We don't need the whole Berries, only their attics up to that point. So as we know, we don't need two digits and lets the eyepiece. So we get the race from fear forward, right, And
copy this and let's go back here
right and let's go for action and see if there's anything regarding action
or anything regarding. Ah, activity event. Something like that, missy. There's not much regarding that.
Drink this very go and drink this. Here we go.
let's see here. Nothing. It doesn't mean it's not there. You can always say search for action.
you can see here you can actually sign another set off custom properties. However, since you're here, you actually search PF sense action.
And then you can select it and poop. There we go. And then you save it. Flew from joining property for ending. Okay,
so where you go, but what about enable And you really have to modify it. But apparently we do have to rewrite it. So let's go ahead and type this again. Obviously, let's remove things that are not required.
So from here, for example,
all right, and let's keep erasing.
I think it's up to here
there. And if you recall there was extra got here that we didn't need, and that's it. Uh,
Um and there's the action captured one. Okay,
well, it's it's safe
and technically wants you to kiss to remove the filter. You can now see
everything in here. Action, peeps in action. Very go See now, just one. Show it in order. But just so you get a general idea, right, and you can save it.
You're gonna have auto discovering.
Sure you can do that. I don't trust it. The he, uh I have mixed feelings about it. Sometimes it works something. This gives you Ron data. And the problem is, if it doesn't know what it is, you're gonna have it. Especially here. That doesn't have, like, little parables. A little field
to have, like identifier, for example. Doesn't say s r c e I, p, you know, in the payload. So now that you're here and you created that, one of things you can do is you can come back to the lock source,
that little click to edit, and here you can select an extension and you can see that the p of seven blocks short extension is there,
and you can save it.
Great. And what happens is
that new locks coming in, right?
You see here, you're going to see that in theory. See, now there you go.
It should load the values specific to this. So let's go ahead and
Oh, I didn't want to do that. Sorry.
You can actually see this variable staying there now
should be working now
that it's reading the variables asked. It's supposed to Obviously, things in the past will not read the proper way. And you can also see that since we actually added the
variables or the values right for source. I, uh, certainly piano those things and we modified actually properties. And we didn't include these properties in the search itself. It's not going to read them right,
So you can see, however, it's detected the source i p now and it's supposed to, and it's detecting two sorts. Poor destination. I pian destination port. That way it's supposed to, and you can actually see
that it's working as intended now, PF since action, you might need to work a little bit more on that to actually do it and a p f sense event name I. Even then we can actually added a swell and edit it. Now, what can we do here? We can actually go and say we're going to do. Ah, you search right now. He seems like a good place to take a chirp. Rick, see you soon.