u-siem-squid 0.0.1

uSIEM Squid proxy parser
1
2
3
4
5
6
7
8
9
10
11
12
13
14
2021-02-14 00:00:24 [26] Request(default/additional/-) testtodeny.com:443 172.17.0.1/172.17.0.1 - CONNECT REDIRECT
2021-02-14 00:00:32 [26] Request(default/additional/-) testtodeny.com:443 172.17.0.1/172.17.0.1 - CONNECT REDIRECT
2021-02-14 00:00:47 [26] Request(default/additional/-) testtodeny.com:443 172.17.0.1/172.17.0.1 - CONNECT REDIRECT
2021-02-14 00:02:30 [26] Request(default/additional/-) violence.com:443 172.17.0.1/172.17.0.1 - CONNECT REDIRECT
2021-02-14 00:02:33 [26] Request(default/additional/-) pornpage.com:443 172.17.0.1/172.17.0.1 - CONNECT REDIRECT


1613260824.636     71 172.17.0.1 NONE/503 0 CONNECT https:443 - HIER_NONE/- -
1613260832.320      0 172.17.0.1 NONE/503 0 CONNECT https:443 - HIER_NONE/- -
1613260836.625    355 172.17.0.1 TCP_TUNNEL_ABORTED/200 5319 CONNECT google.com:443 - HIER_DIRECT/142.250.184.174 -
1613260836.628    287 172.17.0.1 TCP_TUNNEL_ABORTED/200 18353 CONNECT www.google.com:443 - HIER_DIRECT/142.250.184.4 -
1613260847.813      0 172.17.0.1 NONE/503 0 CONNECT https:443 - HIER_NONE/- -
1613260950.574      4 172.17.0.1 NONE/503 0 CONNECT https:443 - HIER_NONE/- -
1613260953.397      0 172.17.0.1 NONE/503 0 CONNECT https:443 - HIER_NONE/- -