It looks like you're new here. If you want to get involved, click one of these buttons!
Each alienvault plugin has 2 required fields..
The configuration section is used for log file location, service related controls and configuring the type of plugin you've created.
The plugin definition section is where you define the regular expression that is used to search each message for a match. It's also used to define variables that you see later within the SIEM.. for example (but not limited to) Source IP, Source Port, Destination IP, Destination Port, Username, Password, Userdata#.
Along with the two required fields above, there is a lesser known section called translation that an be used to convert one value to another. A great example of this is if you captured firewall data that listed an ICMP as a number, but you wanted to display the human readable form to someone.. this is where you'd do it.. For example: Source Quench=4. This means that an ICMP type of 4 would return "Source Quench" rather than a number 4. More on this later though. :)