diff --git a/README.md b/README.md index a72489b..112c2c8 100644 --- a/README.md +++ b/README.md @@ -106,11 +106,11 @@ service: # Input sources (at least 2 required) inputs: unix_sockets: - - name: apache_source - path: /var/run/logcorrelator/apache.sock + - name: http_source + path: /var/run/logcorrelator/http.socket format: json - name: network_source - path: /var/run/logcorrelator/network.sock + path: /var/run/logcorrelator/network.socket format: json # File output diff --git a/architecture.yml b/architecture.yml index 9730f92..59453fb 100644 --- a/architecture.yml +++ b/architecture.yml @@ -200,12 +200,12 @@ inputs: Deux flux de logs JSON via sockets Unix datagram (SOCK_DGRAM). Chaque datagramme contient un JSON complet. unix_sockets: - - name: apache_source + - name: http_source id: A description: > Source A, logs HTTP applicatifs (Apache, reverse proxy, etc.). Schéma JSON variable, champ timestamp obligatoire, headers dynamiques (header_*). - path: /var/run/logcorrelator/apache.sock + path: /var/run/logcorrelator/http.socket permissions: "0666" protocol: unix socket_type: dgram @@ -220,7 +220,7 @@ inputs: description: > Source B, logs réseau (métadonnées IP/TCP, JA3/JA4, etc.). Seuls src_ip et src_port sont requis pour la corrélation. - path: /var/run/logcorrelator/network.sock + path: /var/run/logcorrelator/network.socket permissions: "0666" protocol: unix socket_type: dgram