get_decoders
Retrieve OSSEC decoders to parse and normalize log data. Filter by search terms or filename to find decoders that extract fields like source IP and username.
Instructions
Search and retrieve OSSEC log decoders.
Decoders are used to parse and normalize log data before it is evaluated against rules. They extract fields like source IP, username, program name, etc.
Args: search: Free-text search in decoder names. filename: Filter by decoder file name (e.g., 'local_decoder.xml').
Returns: JSON array of decoder objects with name, parent, fields extracted, etc.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| search | No | ||
| filename | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |