SYSLOG MES2448B
Добавлено: 16 сен 2022 18:52
Здравствуйте!
Подскажите пожалуйста как ловить wireshark syslog сообщения от MES2448B ?
Он в нем выдает при любой команде такое сообщение
Frame 556: 406 bytes on wire (3248 bits), 406 bytes captured (3248 bits) on interface \Device\NPF_{8E24A637-20B7-4B05-8577-D36E1F1A45B1}, id 0
Ethernet II, Src: EltexEnt_d8:2a:c0 (e4:5a:d4:d8:2a:c0), Dst: (98:ee:cb:b0:26:e1)
Internet Protocol Version 4, Src: 192.168.7.5 (192.168.7.5), Dst: 192.168.7.60 (192.168.7.60)
User Datagram Protocol, Src Port: 49153, Dst Port: 514
[truncated]Syslog message: LOCAL0.CRIT: 30-Jan-1970 05:55:35.330 FWL-2- \n\n[**] TCP Non SYN only Pkt [**]\n[Classification: Potentially Bad Traffic] [Priority: 2]\n 01/30-05:55:35.00000 98:EE:CB:B0:26:E1 -> E4:5A:D4:D8:2A:C0 type:0x810
1000 0... = Facility: LOCAL0 - reserved for local use (16)
.... .010 = Level: CRIT - critical conditions (2)
Message [truncated]: 30-Jan-1970 05:55:35.330 FWL-2- \n\n[**] TCP Non SYN only Pkt [**]\n[Classification: Potentially Bad Traffic] [Priority: 2]\n 01/30-05:55:35.00000 98:EE:CB:B0:26:E1 -> E4:5A:D4:D8:2A:C0 type:0x8100 length:0x36\n192.1
Подскажите пожалуйста как ловить wireshark syslog сообщения от MES2448B ?
Он в нем выдает при любой команде такое сообщение
Frame 556: 406 bytes on wire (3248 bits), 406 bytes captured (3248 bits) on interface \Device\NPF_{8E24A637-20B7-4B05-8577-D36E1F1A45B1}, id 0
Ethernet II, Src: EltexEnt_d8:2a:c0 (e4:5a:d4:d8:2a:c0), Dst: (98:ee:cb:b0:26:e1)
Internet Protocol Version 4, Src: 192.168.7.5 (192.168.7.5), Dst: 192.168.7.60 (192.168.7.60)
User Datagram Protocol, Src Port: 49153, Dst Port: 514
[truncated]Syslog message: LOCAL0.CRIT: 30-Jan-1970 05:55:35.330 FWL-2- \n\n[**] TCP Non SYN only Pkt [**]\n[Classification: Potentially Bad Traffic] [Priority: 2]\n 01/30-05:55:35.00000 98:EE:CB:B0:26:E1 -> E4:5A:D4:D8:2A:C0 type:0x810
1000 0... = Facility: LOCAL0 - reserved for local use (16)
.... .010 = Level: CRIT - critical conditions (2)
Message [truncated]: 30-Jan-1970 05:55:35.330 FWL-2- \n\n[**] TCP Non SYN only Pkt [**]\n[Classification: Potentially Bad Traffic] [Priority: 2]\n 01/30-05:55:35.00000 98:EE:CB:B0:26:E1 -> E4:5A:D4:D8:2A:C0 type:0x8100 length:0x36\n192.1