mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2025-12-06 17:22:49 +01:00
add some more fields
This commit is contained in:
@@ -6,6 +6,9 @@
|
||||
{ "rename": { "field": "message2.addl", "target_field": "weird.additional_info", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.notice", "target_field": "weird.notice", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.peer", "target_field": "weird.peer", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.p", "target_field": "weird.p", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.dst", "target_field": "destination.ip", "ignore_missing": true } },
|
||||
{ "rename": { "field": "message2.src", "target_field": "source.ip", "ignore_missing": true } },
|
||||
{ "pipeline": { "name": "zeek.common" } }
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user